Back to all lessons
Awareness Lessons
3 weeks ago

Vodafone Fined €750K for GDPR Breaches Including Third-Party Processor Oversight Failure

Vodafone Spain was fined €750,000 after a data breach on its 'Super WiFi' service exposed inadequate security controls and a critical contractual oversight: a third-party data processor was allowed to begin handling personal data before a formal Data Processing Agreement (DPA) was signed. This violates GDPR Articles 5(1)(f) (integrity and confidentiality), 28 (processor contracts), and 32 (technical and organisational security measures). The case highlights that third-party risk doesn't begin when a vendor causes harm — it begins the moment they are granted access to personal data without proper legal and technical safeguards. Repeat violations were treated as aggravating factors, significantly increasing the penalty. Organisations must treat vendor onboarding as a structured, compliance-gated process — not an afterthought.

Tactical Insight

Immediate actions

  • Audit all active third-party data processors to confirm signed DPAs are in place before any personal data access is granted.
  • Suspend or quarantine any processor relationships where contractual documentation is missing or incomplete.

Long-term improvements

  • Implement a formal vendor onboarding gate process that legally and technically blocks data access until DPAs, security assessments, and access controls are verified.
  • Establish a Third-Party Risk Management (TPRM) programme that continuously monitors processor compliance with GDPR Article 28 obligations.
  • Maintain a centralised processor register with contract expiry dates, DPA status, and security review schedules.

Detection & Oversight measures

  • Conduct regular internal audits mapping data flows to processor agreements to detect unauthorised or undocumented processing activities.
  • Integrate GDPR compliance checkpoints into procurement and contract management workflows to catch gaps before go-live.