Administrative fines in the total amount of €45.000.000 imposed on Vodafone by German Supervisory Authority for Data Protection

The German Federal Supervisory Authority for Data Protection imposed a fine of €15 000 000 for insufficient supervision and auditing procedures regarding the partner agencies and imposed a reprimand for the weaknesses in the IT systems. Furthermore, it imposed a fine of €30 000 000 for insufficient security measures regarding the online service portal.

The German Federal Supervisory Authority (SA) launched investigations regarding Vodafone GmbH’s partner agencies and its online service portal after having received external information outside of any complaints.

Vodafone GmbH is a telecommunications service provider operating on the German market. The company uses different distribution channels, including local shops, of which some are operated by partner agencies. They are acting under the Vodafone brand and are bound to the company’s instructions. Their IT systems are based on hard- and software provided by Vodafone. Data Processing Agreements govern the processing of customer data.

Investigations discovered privacy related weaknesses in the processes to supervise and audit the processors as well as weaknesses in the IT systems leading to the risk of customer data being misused for fraud. Such risks actually materialized in some cases.

Furthermore, Vodafone offers an online service portal for its customers. When used in combination with the company’s hotline, investigations by the German Federal SA found weaknesses in the authentication process for the customer accounts that could lead to misuse of eSIMs. The company has taken steps to remediate any shortcomings found. (source: edpb.europa.eu/photo freepik.com)

Comments

Popular posts from this blog

Fully-funded PhD position in AI, Law and Public Power

Cancellation of a flight: The refund of the airline ticket price must include the commission collected by an intermediary at the time of purchase (CJEU)

The Concept of "Habitual Residence" as a Jurisdictional Basis in International Parental Responsibility Disputes: The Cypriot Approach

Pretextual Threats of Collective Redundancies: A Form of Workplace Harassment (Mobbing) under Cyprus Law

Ombudsman inquiry on Commission President’s text messages is a wake-up call for EU

Annual Report on the execution of the European Court's judgments and decisions

Personal data collected by means of body cameras worn by ticket inspectors on public transport – Legal basis for the obligation on the data controller to provide information to the data subject (CJEU)