[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv_C15gOdajAYl_lTonVH_DoNEf8gKWHYHo28rCJIQ60":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"9eae13a4-38df-409d-bb75-b46b8c2c629b","vodafone-espaa-fined-750k-for-gdpr-failures-including-false-encryption-claims","052122ce-c128-440c-940b-d9f210fd31cd","Vodafone España Fined €750K for GDPR Failures Including False Encryption Claims","Vodafone España suffered a data breach in its Super WiFi service and was fined €750,000 by Spain's AEPD for multiple GDPR violations, including inadequate security measures, absence of a valid data processor agreement, and falsely claiming encryption was in place. The lack of a proper Article 28 data processing agreement means third-party data processors were operating without legally required contractual safeguards, creating uncontrolled risk exposure for personal data. Misrepresenting security controls (such as claiming encryption that did not exist) is particularly serious as it undermines regulatory oversight and incident accountability. This case is aggravated by repeat offences in 2021 and 2022, demonstrating a systemic failure to embed a culture of data protection compliance. Organisations processing large volumes of personal data face heightened scrutiny and proportionally larger penalties when violations recur.","**Immediate actions:**\n- Audit all active data processor relationships and ensure valid, GDPR Article 28-compliant Data Processing Agreements (DPAs) are signed before any processing begins.\n- Conduct an honest internal review of all claimed security controls (e.g., encryption at rest and in transit) to verify they are actually implemented and functioning.\n- Notify the DPA proactively if previously reported security measures are found to be inaccurate or insufficient.\n\n**Long-term improvements:**\n- Establish a formal Third-Party Risk Management (TPRM) programme that includes periodic technical audits of processors to validate contractual security commitments.\n- Implement a Data Protection by Design and by Default framework (GDPR Article 25) so that security controls are mandated and verified at the start of every new service or product.\n- Create a repeating annual compliance review cycle specifically targeting previous regulatory findings to prevent repeat infringements.\n\n**Detection and accountability measures:**\n- Deploy continuous monitoring of data flows involving personal data to detect unauthorised access or anomalous processor behaviour in near real-time.\n- Maintain a centralised register of all data processing activities (GDPR Article 30 RoPA) and cross-reference it with verified technical security controls on a quarterly basis.\n- Assign named data protection ownership at the executive level for each high-risk processing activity to ensure accountability when controls fail.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 28 – Data processor agreements","GDPR Article 32 – Security of processing","GDPR Article 25 – Data protection by design and by default","GDPR Article 30 – Records of processing activities","NIST SP 800-53 SA-9 – External Information System Services","NIST SP 800-53 SC-28 – Protection of Information at Rest","NIST SP 800-53 CA-3 – System Interconnections","CIS Control 3 – Data Protection","CIS Control 15 – Service Provider Management","ISO\u002FIEC 27001:2022 Annex A 5.19 – Information security in supplier relationships","ISO\u002FIEC 27001:2022 Annex A 8.24 – Use of cryptography","ITIL 4 – Risk Management and Supplier Management practices","published","2026-09-23T10:21:15.064684+00:00","2026-09-23T10:21:14.93+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00240-2025&diff=53178&oldid=53153","aepd-spain-ps-00240-2025-c36710","AEPD (Spain) - PS-00240-2025",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":46,"name":47,"slug":48,"description":49,"color":50},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]