Xfera Moviles S.A.

€60K($65K USD)final

Date Issued

2019-11-19

Regulation

Authority

Spanish Data Protection Authority (AEPD)

Country

Spain

Violation Type

Failure to implement sufficient measures to ensure information security

Currency

EUR

Violation Summary

A private individual received an SMS from Xfera Móviles which was actually addressed to a different person and which included personal details of that third party person. The information included personal details as well as login details to the Xfera Móviles website for the third party person.

Articles Violated

Art. 32 GDPR

Other Fines for Xfera Moviles S.A.

DateRegulationAmount (USD)Type
2022-02-01GDPR$216,000Non-compliance with lawful basis for data processing
2020-12-09GDPR$43,200Failure to comply with data processing principles
2020-11-06GDPR$21,600Failure to implement sufficient measures to ensure information security
2020-09-25GDPR$64,800Failure to comply with data processing principles
2020-07-23GDPR$5,400Non-cooperation with Data Protection Authority
2020-07-20GDPR$75,600Failure to comply with data processing principles
2020-07-10GDPR$59,400Non-compliance with subjects' rights protection safeguards
2020-07-02GDPR$5,400Non-cooperation with Data Protection Authority
2020-06-15GDPR$81,000Non-compliance with subjects' rights protection safeguards
2020-06-09GDPR$42,120Non-compliance with lawful basis for data processing