AEPD (Spain) - EXP202311911

From GDPRhub
AEPD - EXP202304821
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 6(1) GDPR
Article 6(1)(a) GDPR
Article 6(1)(b) GDPR
Article 82(2) GDPR
Type: Complaint
Outcome: Upheld
Started: 11.06.2025
Decided: 30.05.2025
Published: 10.06.2025
Fine: 200,000 EUR
Parties: DIGI SPAIN TELECOM, S.L.
National Case Number/Name: EXP202304821
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: ap

The DPA dismissed the internal appeal of a telecommunications company, and imposed a €200,000 fine for duplicating SIM cards for unauthorised third parties.

English Summary

Facts

DIGI SPAIN TELECOM, S.L. (the controller) is a telecommunications company. On 6 April 2021, a third person requested to duplicate the data subject’s SIM card at a store that sold the controller's products. The data subject lost phone service. Two hours later, the data subject obtained a new SIM card duplicate at a different store, which gave them access to the service again. According to the data subject, the controller did not take any measures to verify the identity of the person requesting the SIM card duplicate. Furthermore, the third person committed identity theft, because the data subject noticed an unauthorised bank transfer from their account (this was not addressed in the case).

The data subject presented a complaint to the DPA on 12 July 2023. The DPA imposed a €200,000 fine on the controller for duplicating SIM cards for unauthorised third parties on 8 November 2024. The controller then filed an internal appeal to the DPA on 11 December 2024.

The controller argued that its procedure for situations such as these that was carefully followed, and allowed it to process data lawfully in accordance to its obligations. The controller also contested the unauthorised bank transfer as a result of the SIM duplicate. In addition, it argued that it could not be held completely responsible for identifying and mitigating fraud. The controller requested a lower fine based on mitigating circumstances, stating that the DPA had set a disproportionately high fine. Among others, it argued that it had effectively solved the situation and that it did not process special categories of personal data.

Holding

According to the DPA, the controller duplicated the data subject’s SIM card without a valid legal basis under Article 6(1) GDPR, despite the protocols set in place by the controller. The protocol to verify an individual’s identity was based solely on matching specific data with its database, and did not ensure that the data subject was involved or aware. The DPA stated that the coincidence of the data provided by an individual and the database is not enough to process the data under consent (Article 6(1)(a) GDPR) or any other legal basis. The issue in this case was not that the controller did not follow its internal protocol or lacked security measures, but rather that it was processing the personal data without a valid legal basis.

The DPA dismissed the mitigating circumstances presented by the controller. The DPA argued that the controller had not taken the initiative in resolving the situation or detected the fraud. Therefore, applying the mitigating circumstance under Article 82(2)(c) GDPR would “artificially” decrease the fine and its deterrent effect. Furthermore, while the processing did not involve special categories of data, the DPA considered that the data (full name and ID) had a sensitive nature. The unauthorised access was particularly serious because it was accessed with the intent of committing identity theft, and it involved a loss of control of the data subject over their data.

Finally, the DPA highlighted three previous fines it had given the controller for duplicating a SIM card without a legal basis, each resulting in a €70,000 fine. As a very important telecommunications company in Spain, the DPA considered that the controller had the responsibility to more rigorously guarantee the protection of personal data principles according to national case law[1].

The DPA maintained the €200,000 fine imposed on the controller in its previous decision on the grounds that the controller had not presented new legal facts.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

1/20

 File No.: EXP202311911

RESOLVE ON APPEAL FOR RECONVERSION

The appeal for reconsideration filed by DIGI SPAIN TELECOM, S.L.U. has been examined. (hereinafter, the appellant) against the resolution issued by the Director of the Spanish Data Protection Agency dated November 8, 2024, and based on the following:

FACTS

FIRST: On November 8, 2024, the Director of the Spanish Data Protection Agency issued a resolution in case EXP202311911, imposing a fine of €200,000 (two hundred thousand euros) on DIGI SPAIN TELECOM, S.L.U. for a violation of Article 6.1 of the GDPR, as defined in Article 83.5 of the GDPR.

This resolution, which was notified to the appellant on November 11, 2024, was issued after the corresponding sanctioning procedure had been processed, in accordance with the provisions of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and, additionally, Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), regarding the processing of sanctioning procedures.

SECOND: The following facts were recorded as proven facts of the aforementioned sanctioning procedure:

FIRST. – On April 6, 2021, a third party appeared at a DIGI point of sale to obtain a duplicate of the complainant's SIM card.

SECOND. – The two screenshots of the DIGI system provided on October 11, 2023, in response to this Agency's request for information from the respondent, and recorded in the file, show the issuance of two duplicate SIM cards for the complainant.

- The first one shows that the duplicate SIM card was issued on April 6, 2021, at 2:21 PM at a DIGI point of sale, leaving the complainant without a line.

- The second one shows that a new duplicate SIM card was issued, so that the initial duplicate became inactive on April 6, 2021, at 4:47 PM, and the complainant regained access to the line.

THIRD. – From the screenshots provided by DIGI, dated October 11, 2023, it is clear that the process for verifying the applicant's identity, applied to this case in force at the time of the events, to obtain a duplicate SIM card, was as follows:

(…)
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 2/20

THIRD: On December 11, 2024, the appellant filed an appeal for reconsideration with this Spanish Data Protection Agency,

basically based on the fact that the appellant considers that, based on the proven facts, it is possible to conclude that DIGI had a procedure in place for this purpose, which was scrupulously followed, and which allowed it to carry out lawful data processing, in accordance with its obligations.

Furthermore, DIGI states that it is making every effort to identify and mitigate fraud attempts, and cannot be held absolutely responsible for detecting them; it is a third party that has the claimant's telephone, identification, and banking information and complies with the protocol.

Furthermore, it points out that the AEPD's responsibility is based solely on the result.

Likewise, DIGI alleges that the AEPD unequivocally imposes objective liability on it, in which, regardless of the diligence and measures deployed, the entity's guilt is declared.

Regarding the lack of proportionality of the proposed sanction, and that, after the appropriate procedures, a resolution be issued indicating the closing of the procedure EXP202311911, and outlines sanctions imposed on other companies in the telecommunications sector due to the occurrence of Sim Swapping fraud.

Digi requests that the following mitigating circumstances be considered:

The respondent party effectively resolved the incident that is the subject of the complaint (Article 83.2 c GDPR).

That special categories of data were never processed (Article 83.2 g GDPR).

The degree of cooperation between DIGI and the AEPD (Spanish Data Protection Agency).

The non-existent benefit obtained by DIGI (Article 83.2 k GDPR).

Alternatively, if the AEPD rules contrary to DIGI's legal basis, the AEPD is requested to terminate the procedure by issuing a warning and, ultimately, to moderate or adjust the sanction included in the Resolution notified to DIGI.

LEGAL GROUNDS

I

Jurisdiction

The President of the Spanish Data Protection Agency is competent to rule on this appeal, in accordance with the provisions of Article 123 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP) and Article 48.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter, LOPDGDD).

II
Response to the allegations presented

In relation to the statements made by the appellant, essentially reiterating the allegations already presented throughout the sanctioning procedure, it should be noted that all of them have already been analyzed and dismissed in Legal Grounds II to V of the Appealed Resolution, as transcribed

below:

<<II
Response to the allegations presented

In response to the allegations presented by the respondent entity, the following should be noted:

The fraudulent intervention of a third party has revealed a deficient analysis of the risks, as well as the insufficient implementation, review, and control of security measures by the operator. A third party other than the data subject has exceeded the security measures established by DIGI. This shows us that the identification of the data subject was not carried out with sufficient guarantees, regardless of whether the identification was carried out by the data subject themselves or by a fraudulent third party.

In short, there was a lack of appropriate security measures and a failure to comply with the obligations arising from proactive responsibility, especially when the "errors" persist over time.

In this regard, it should be noted that the fact that we are dealing with third-party fraud makes it necessary to ensure that the person to whom the duplicate SIM card is issued is who they claim to be, and appropriate preventive measures must be adopted to verify the identity of a person whose data will be processed, as recognized in the Seventh Legal Basis of the San, SCA, of May 5, 2021 ("On the other hand, regarding the fact that we are dealing with third-party fraud, as we stated in the San of October 3, 2013 (Rec. 54/2012): "Precisely for this reason, it is necessary to ensure that the person contracting is who they claim to be, and appropriate preventive measures must be adopted to verify the identity of a person whose personal data will be processed...").

Throughout this procedure, DIGI has repeatedly stated that fraudulent duplicates of the cards were produced after the fraudsters had bypassed their security policy. It is considered inevitable that, despite the existence of the security policy, there may be cases in which, through certain mechanisms, said security policy can be fraudulently bypassed, without any blame being placed on DIGI.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 4/20

However, it has been proven that DIGI's security policy has been insufficient to adequately protect the fundamental rights of the complainant whose SIM card was fraudulently duplicated.

Regarding the fact that DIGI has not made available to the alleged criminals any personal information of the complainant other than that which they had previously, and that, consequently, no unauthorized processing of personal data has taken place.

Indeed, the issuance of a duplicate is not sufficient to carry out Banking transactions on behalf of the data subjects are certainly necessary to complete the fraud, requiring a third party to "impersonate" the data subject with the financial institution.

However, in order to carry out these transactions via mobile phone, it is necessary to have access to the phone, and one of the methods is precisely obtaining a duplicate card. When this duplicate card is issued to a third party other than the cardholder, it entails, a priori, processing that violates the principle of lawfulness, since a third party is processing data, since it has access to it, without any legal basis.

For this reason, this is a process in which the due diligence provided by the operators is essential to prevent this type of fraud and violations of the GDPR.
This due diligence translates into the establishment of appropriate measures to ensure that data processing complies with the GDPR.

In the present case, it can be inferred that DIGI provided a duplicate SIM card to a third party other than the legitimate owner of the mobile line, after the third party overrode the existing security policy.

Denying the existence of negligent conduct on the part of DIGI would be equivalent to acknowledging that its conduct—by action or omission—was diligent. Obviously, we do not share this perspective of the facts, since the lack of due diligence has been proven. The SAN ruling of October 17, 2007 (rec. 63/2006) is very illustrative, based on the fact that these are entities whose activity involves the continuous processing of customer data, stating that "...the Supreme Court has been understanding that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. And in assessing the degree of diligence, the professionalism of the individual must be especially considered, and there is no doubt that, in the case now under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."

As for the fact that the criminals were unable to obtain personal data through DIGI, and therefore there cannot be a breach of protective measures, this cannot be considered true. It is important to note that access to a duplicate SIM card that makes its owner identifiable meets the definition of personal data in Article 4.1 of the GDPR.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/20

Regarding DIGI's liability, it should be noted that, in general, DIGI processes its customers' data under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the execution of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures. In other cases, it bases the lawfulness of the processing on the bases provided for in Article 6.1 a), c), e), and f) of the GDPR.

Certainly, the principle of liability provided for in Article 28 of the LRJSP (Law of Public Prosecutors)

provides that: "Only natural and legal persons may be sanctioned for acts constituting an administrative infraction, as well as, when a law recognizes their capacity to act, groups of affected parties, unions and entities without legal personality, and independent or autonomous assets, who are found liable for such acts based on intent or negligence."

However, the method of attributing liability to legal persons does not correspond to the forms of intentional or reckless culpability that are attributable to human conduct. Thus, in the case of infractions committed by legal persons, although the element of culpability must be present, it is necessarily applied differently than it is with respect to natural persons.

According to STC 246/1991, "(...) this different construction of the imputability of the authorship of the infringement to the legal entity arises from the very nature of the legal fiction to which these subjects respond. They lack the volitional element in the strict sense, but not the capacity to violate the rules to which they are subject.

The capacity to violate and, therefore, direct blameworthiness derives from the legal asset protected by the rule being violated and the need for such protection to be truly effective and the risk that, consequently, must be assumed by the legal entity that is subject to compliance with said rule" (in this regard, STS of November 24, 2011, Rec 258/2009).

To the above, it should be added, following the judgment of January 23, 1998, partially transcribed in the Supreme Court rulings of October 9, 2009, Rec 5285/2005, and of October 23, 2010, Rec 1067/2006, that "although the culpability of the conduct must also be subject to proof, it must be considered, in order to assume the corresponding burden, that the volitional and cognitive elements necessary to assess such conduct ordinarily form part of the proven typical conduct, and that their exclusion requires proof of the absence of such elements, or, in its normative aspect, that the due diligence required by the person claiming their absence has been exercised; in short, invoking the absence of culpability is not sufficient to exonerate a person from typically unlawful conduct."

Consequently, the lack of culpability is dismissed. Ultimate responsibility for the processing remains with the data controller, who is the party responsible for determining the existence of the processing and its purpose. It should be recalled that, as a general rule, operators process their customers' data under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the execution of a contract to which the data subject is a party (...). In this regard, DIGI has a network of approved sales representatives, points of sale, and distributors through a distribution contract to offer DIGI services. Among these services offered through its points of sale is the production of SIM card duplicates corresponding to a mobile phone line. Regarding non-compliance with the principle of proportionality, the GDPR expressly provides for the possibility of scaling, through the provision of fines that can be adjusted, taking into account a series of circumstances in each individual case, the existence of which was duly justified in the agreement initiating this procedure.

Regarding the imposition of a warning, reprimand, or the adoption of corrective measures pursuant to Article 58 of the GDPR, a deterrent fine is one that has a genuine deterrent effect. In this regard, the Judgment of the CJEU of 13 June 2013, Versalis Spa v Commission, C-511/11, ECLI:EU:C:2013:386, states:

“94. With regard, first of all, to the reference to the aforementioned Showa Denko v Commission judgment, it should be noted that Versalis misinterprets it. Indeed, the Court of Justice, in stating in paragraph 23 of that judgment that the deterrent factor is assessed by taking into account a multitude of elements and not only the particular situation of the undertaking concerned, was referring to points 53 to 55 of the Opinion presented in that case by Advocate General Geelhoed, who had essentially stated that the deterrent factor may be intended not only to achieve “general deterrence,” defined as an action to disincentivize all companies, in general, from committing the infringement in question, but also "specific deterrence," consisting of discouraging the specific defendant from violating the rules again in the future. Therefore, the Court of Justice only confirmed, in that judgment, that the Commission was not required to limit its assessment to factors related solely to the specific situation of the company in question. “102. According to settled case law, the objective of the deterrent multiplier factor and of the consideration, in this context, of the size and overall resources of the undertaking in question lies in the desired impact on the undertaking in question, since the penalty must not be insignificant, particularly in relation to the undertaking's financial capacity (to this effect, see, in particular, Case C-413/08 P Lafarge v Commission [2010] ECR I-5361, paragraph 104, and the order of 7 February 2012 in Case C-421/11 P Total and Elf Aquitaine v Commission, paragraph 82).”

We must address the unique circumstances of the claim presented, through which it can be established that, from the moment the impersonator replaces the SIM, the victim's phone is left without service, transferring control of the line to the impersonators. Consequently, their powers of disposal and control over their personal data are affected, which constitute part of the fundamental right to data protection, as stated by the Constitutional Court in Ruling 292/2000, of November 30, 2000 (Legal Notice 7). Thus, obtaining a duplicate SIM card allows, under certain circumstances, access to contacts or to applications and services that have the password recovery procedure of sending an SMS with a code to change passwords. In short, they will be able to impersonate those affected, gaining access to and control, for example: email accounts; bank accounts; applications such as WhatsApp; social networks such as Facebook or Twitter, and much more. In short, once the impersonators change their password, they lose control of their accounts, applications, and services, which poses a significant threat.
Ultimately, it is the data controller who has the obligation to integrate

the necessary safeguards into the processing, in order to, pursuant to the principle of proactive accountability, comply and be able to demonstrate compliance, while respecting the fundamental right to data protection.

III

Unfulfilled Obligation

Well, the defendant is charged with committing an infringement for violating Article 6 of the GDPR, "Lawfulness of Processing," which sets forth in Section 1 the circumstances in which the processing of third-party data is considered lawful:

"1. Processing will only be lawful if at least one of the following conditions is met:

a) the data subject has given consent to the processing of their personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures;

c) processing is necessary for compliance with a legal obligation applicable to the data controller;

d) processing is necessary to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data subject." to the data controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. The provisions of point (f) of the first paragraph shall not apply to processing carried out by public authorities in the exercise of their tasks.

The issuance of a duplicate SIM card necessarily entails the processing of personal data, as it is carried out on the line and identity of the data subject. Such processing must comply with a legal basis that legitimizes it, as required by the aforementioned Article 6.1 of the GDPR.

In this case, the issuance of the duplicate SIM card at the request of a third party without the intervention or consent of the data subject constitutes a lack of a valid legal basis for such data processing. Although DIGI claims to follow its own protocols, this is not sufficient to justify the lawfulness of the processing under the GDPR, as these protocols do not satisfy the need for a legitimate basis.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/20

The identity verification procedure described by DIGI, which is based solely on the coincidence of certain data in its database, does not adequately guarantee compliance with the GDPR because:

 It does not prove the effective involvement of the data subject in the process.

 The mere coincidence of data does not guarantee consent or any other legal basis under Article 6.1 that legitimizes the processing.

Therefore, the issuance of the duplicate SIM card under these conditions constitutes the processing of personal data without a legal basis and, consequently, a violation of Article 6.1 of the GDPR, given that it was carried out without complying with any of the legitimate grounds for such processing. Liability does not lie in the failure to comply with DIGI's internal protocol, but rather in the absence of a valid legal basis in accordance with the provisions of the GDPR.

Based on the evidence available, it is considered that the conduct of the respondent violates Article 6.1 of the GDPR, which constitutes a violation classified as Article 83.5.a) of the aforementioned Regulation 2016/679.

In this regard, Recital 40 of the GDPR states:

“(40) In order for processing to be lawful, personal data must be processed with the consent of the data subject or on another legitimate basis established by law, whether by this Regulation or by other Union or Member State law to which this Regulation refers, including the

necessity for compliance with a legal obligation applicable to the controller or the
necessity for the performance of a contract to which the data subject is party or in order to
take steps at the request of the data subject prior to entering into a contract.”

Based on the foregoing, DIGI is considered to have violated Article 6.1 of the GDPR.

IV
Classification and qualification of the violation

The violation is defined in Article 83.5 of the GDPR, which states:

“5. Violations of the following provisions shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of a company, by an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:

a) the basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9.”

For the purposes of the statute of limitations for infringements, Article 72.1 of the LOPDGD classifies as a very serious infringement, with the statute of limitations being three years, “b)

The processing of personal data without any of the conditions for the lawfulness of processing established in Article 6 of Regulation (EU) 2016/679 being met.”

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 9/20

V
Sanction of a fine. Determining the Amount

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:

“Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for the infringements of this Regulation indicated in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.”

“Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58(2)(a) to (h) and (j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:

a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered by them;

b) the intentionality or negligence involved in the infringement;

c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;

d) the degree of responsibility of the controller or processor, taking into account any technical or organizational measures implemented pursuant to Articles 25 and 32;

e) any previous infringements committed by the controller or processor processing;

f) the degree of cooperation with the supervisory authority in order to remedy the breach and mitigate the potential adverse effects of the breach;

g) the categories of personal data affected by the breach;

h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;

i) where measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and

k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the breach.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 10/20

Regarding section k) of Article 83.2 of the GDPR, the LOPDGDD, Article 76, "Sanctions and corrective measures", provides:

"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679,

the following may also be taken into account:

a) The continuous nature of the infringement.

b) The connection between the infringer's activity and the processing of personal data.

c) The benefits obtained as a result of the infringement.

d) The possibility that the affected party's conduct could have led to the infringement.

e) The existence of a merger by absorption process subsequent to the infringement, which cannot be attributed to the acquiring entity.

f) The violation of the rights of minors.

g) Having, when not mandatory, a data protection officer.

h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where there are disputes between them and any interested party.

In accordance with the transcribed provisions, for the purposes of determining the fine to be imposed on the respondent, as the party responsible for an infringement classified as Article 83.5.a) of the GDPR, the following factors are considered concurrent:

DIGI requests that the following mitigating circumstances be assessed:

(I) "The respondent party effectively resolved the incident that was the subject of the complaint" (Article 83.2 c) of the GDPR).
(II) "Special categories of data were not processed at any time" (Article 83.2 g).
(III) "Cooperation with the supervisory authority in responding to the communication of the complaint and providing the requested information" (Article 83.2 f) of the GDPR).
(IV) "The absence of benefits obtained through the infringement" (Article 83.2 k) of the GDPR and Article 76.2 c) of the GDPR. LOPDGDD.

None of the invoked mitigating circumstances are admitted.

The admission that the fact that the respondent has effectively resolved the incident in question (Article 83.2 c) of the GDPR) operates as a mitigating circumstance, partially nullifies the deterrent purpose served by the sanction. Accepting DIGI's argument in a case like the one at hand would mean introducing an artificial reduction in the sanction that truly should be imposed; this reduction results from considering the circumstances of Article 83.2 of the GDPR that must be assessed.
In the present case, the resolution of the incident was not carried out on DIGI's own initiative, nor because this entity had detected the fraud itself, but rather through the intervention of the complainant himself, who, finding himself unable to service, they go to another point of sale to activate them again. At that time, they are given a new duplicate SIM card, which cancels the previous one obtained fraudulently.

Article 83.2g) of the GDPR states, "At no time have special categories of data been processed."

The data processed by DIGI is sensitive data, used to identify its customers in the process of obtaining a duplicate SIM card. These data are the name, surname, and ID number. These are personal data associated with a telephone line owned by a user, which is obtained for the purpose of impersonating them. This personal data, whose unauthorized access is particularly serious, is notwithstanding the fact that, for the purpose of issuing the duplicate SIM card, personal data such as the name, surname, and ID number of the holder have been processed.

Article 83.2.f) of the GDPR refers to the "degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the potential adverse effects of the infringement;"

The respondent's response to the information request from the Inspection Subdirectorate did not fulfill these purposes, and therefore does not fall within this mitigating circumstance.

Regarding the application of Article 76.2.c) of the LOPDGDD, in conjunction with Article 83.2.k), the lack of benefits obtained, it should be noted that such a circumstance can only operate as an aggravating factor and in no case as an attenuating circumstance.

Article 83.2.k) of the GDPR refers to "any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement." And Article 76.2c) of the LOPDGDD states that "2. Pursuant to Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account: [...] c) Benefits obtained as a result of committing the infringement." Both provisions
mention as a factor that can be taken into account in the grading of the sanction

the "benefits" obtained, but not the "absence" of these, which is what DIGI alleges.

Furthermore, according to Article 83.1 of the GDPR, the imposition of fines is governed by the following principles: they must be individualized for each particular case, be effective, proportionate, and dissuasive. Accepting that the absence of benefits operates as a mitigating factor is contrary to the spirit of Article 83.1 of the GDPR and the principles that govern the determination of the amount of the fine. If, following the commission of a GDPR violation, the absence of benefits is considered a mitigating factor, the deterrent purpose served by the sanction is partially nullified. Accepting DIGI's argument in a case such as the one at hand would mean introducing an artificial reduction in the sanction. truly must prevail; the one resulting from considering the circumstances of Article 83.2 of the GDPR, which must be assessed.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 12/20

The Administrative Litigation Division of the National Court has noted that the fact that, in a specific case, not all the elements that constitute a circumstance modifying liability, which by its nature is aggravating, are present, cannot lead to the conclusion that such circumstance is applicable as a mitigating circumstance. The ruling made by the National Court in its Supreme Court of May 5, 2021 (Recital No. 1437/2020)—even though that resolution deals with the circumstance of section e) of Article 83.2 of the GDPR, the commission of prior infractions—can be extrapolated to the question raised. The
claimed claim that the "absence" of profits be accepted as a mitigating factor, given that

both the GDPR and the LOPDGDD refer only to "profits obtained."

For the purposes of graduating the amount of the fine proposed to be imposed on DIGI
for the violation of Article 6.1 of the GDPR, we consider that the following circumstances exist, which operate as aggravating factors:

- The circumstance of Article 83.2 e) GDPR: "Any previous infringement committed
by the controller or processor."

Recital 148 of the GDPR states that "In order to strengthen the application of the

rules of this Regulation […]" and indicates in this regard that "However, particular attention should be paid to […] or any relevant previous infringement […]."

Thus, in accordance with Article 83.2 e) GDPR, in determining the
amount The administrative fine sanction cannot fail to consider all prior violations by the data controller or processor in order to assess the unlawfulness of the conduct analyzed or the culpability of the offender.

Furthermore, a correct interpretation of Article 83.2.e) GDPR cannot ignore the purpose of the regulation: to decide the amount of the administrative fine in the individual case at hand, always ensuring that the sanction is proportional, effective, and dissuasive.

There are numerous sanctioning procedures processed by the AEPD in which the respondent has been sanctioned for violating Article 6.1 GDPR:

i.EXP 202104009 Resolution issued on March 15, 2023, imposing a fine of €70,000. The facts involved a duplicate card. SIM card

fraudulent without legitimacy.

ii.EXP202201226. Resolution issued on March 14, 2023, imposing a fine of €70,000. The facts involved a fraudulent duplicate SIM card without legitimacy.

iii.EXP202204881 Resolution issued on June 2, 2023, imposing a fine of €70,000. The facts involved a fraudulent duplicate SIM card without legitimacy.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 13/20

- The evident link between the defendant's business activity and the processing of personal data of clients or third parties (Article 83.2.k of the GDPR
in relation to Article 76.2.b of the LOPDGDD).

The defendant's business activity necessarily processes personal data, as it is a very important telecommunications company in Spain. This characteristic of its business activity has a significant impact on the diligence it must display in compliance with the principles governing the processing of personal data and on the quality and effectiveness of the technical and organizational standards it must implement to ensure respect for the fundamental right.

The ruling of the National Court of 17/10/2007 (rec. 63/2006), in which, with respect to entities whose activity involves the continuous processing of customer data, states that "...the Supreme Court has held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. And in assessing the degree of diligence, the professionalism or lack thereof of the subject must be especially considered, and there is no doubt that, in the case now under examination, when the appellant's activity involves constant and extensive handling of personal data, emphasis must be placed on the rigor and exquisite care required to comply with the legal provisions in this regard."

The sanction to be imposed on the defendant must be graded and set at €200,000 for the violation of Article 83.5 a) of the GDPR, classified as very serious for the purposes of the statute of limitations in Article 72.1 b) of the LOPDGDD.

The Agency's resolution omits both the DIGI procedure stipulated for this purpose and the diligence employed in handling the attempted fraud. In this regard, it should be noted that in this case, the violation is not based on insufficient or inadequate security measures, but rather on a lack of lawfulness in the processing of personal data, which entails the issuance of a duplicate card and its delivery to a third party, without the cardholder even being aware of such processing.

Article 6.1 establishes that the processing of personal data is only lawful if at least one of the conditions set forth in the aforementioned article is met. In this case, the violation of the principle of lawfulness is manifested in the improper processing of the personal data of the respondent, who was not the actual applicant for the duplicate card.

This type of procedure requires adequate verification of the applicant's identity, and

this requires establishing measures to ensure correct identification. The establishment of these measures or protocols, as well as their monitoring and attention by the responsible entity, serves to assess the conduct and degree of diligence employed by the entity, but these are not the determining factors of the violation.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/20

DIGI issued a duplicate SIM card without the consent of the line holder and handed it over to a third party without a valid legal basis. This act constitutes unlawful data processing.

In short, in this case, the sanction is not the existence or absence of technical and organizational measures, but rather the fact that, in this specific case, the processing of the complainant's personal data was carried out without complying with the lawfulness requirements established in Article 6.1 of the GDPR. The violation of this article confirms that the respondent allowed unauthorized processing of the data, thereby violating the complainant's rights.

In any case, the measures implemented by DIGI are the minimum required of any organization with the characteristics and in the context in which a telecommunications operator operates.

In this sense, the mere existence of a security policy cannot justify a violation of the lawfulness principle set forth in Article 6.1 of the GDPR. In addition to existing measures, these measures must be effective, and the data controller must ensure that they are strictly adhered to at all times. Otherwise, the measures adopted lack validity and may lead to unlawful processing, as occurred in the present case.

Therefore, the respondent cannot claim to be exonerated from its liability by appealing to the existence of minimum measures, even less so when the failure lay in the application of those measures, allowing a violation of the lawfulness of the processing.

DIGI points out that neither the claim nor the evidence in the file indicates that any personal information of the line owner was accessed as a result of making the duplicate SIM card available. In this sense, this statement does not exempt the respondent from liability, since the mere issuance of a SIM card and its delivery to an unauthorized third party already entails a violation of the principle of lawfulness, as it is considered the processing of personal data.

Regarding the degree of liability that may be attributed to them, DIGI insists that they cannot be held accountable for the actions of a third party beyond their control, that is, the security measures implemented by one banking institution or another, or even the fact that the affected party has online banking. In relation to this allegation, in addition to what has already been indicated above, the degree of liability falls within its scope and not that of third parties. It should be noted that the San (Administrative Litigation Chamber) of May 5, 2021, establishes that: "On the other hand, regarding the fact that we are dealing with fraud by a third party, as we stated in the San (Administrative Litigation Chamber) of October 3, 2013 (Recital 54/2012): "Precisely for this reason, it is necessary to ensure that the person contracting is who they truly claim to be, and appropriate preventive measures must be adopted to verify the identity of a person whose personal data will be processed."

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 15/20

Regarding DIGI's liability, it should be noted that, in general, DIGI processes the data of its clients under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the performance of a contract to which the data subject is a party or for the application, at the request of the data subject, of pre-contractual measures. In other cases, the lawfulness of the processing is based on the bases provided for in Article 6.1. a), c), e), and f) of the GDPR.

Certainly, the principle of liability provided for in Article 28 of the LRJSP (Law on the Protection of Personal Data),
stipulates that: "Only natural and legal persons may be sanctioned for acts constituting an administrative infringement, as well as, when a law recognizes their capacity to act, groups of affected parties, unions and entities without legal personality, and independent or autonomous assets, who are found to be liable for such acts due to intent or negligence."

However, the method of attributing liability to legal entities does not correspond to the forms of wilful or reckless culpability that are attributable to human conduct. Thus, in the case of violations committed by legal entities, although the element of culpability must be present, it is necessarily applied differently than it is to natural persons.

According to STC 246/1991, of December 19, Rec 1274/1988, "(...) this distinct construction of the imputability of the authorship of the violation to the legal entity arises from the very nature of the legal fiction to which these subjects respond. They lack the volitional element in the strict sense, but not the capacity to violate the rules to which they are subject.

The capacity to infringe and, therefore, direct blameworthiness arising from the legal asset protected by the infringed rule and the need for such protection to be truly effective, and the risk that, consequently, must be assumed by the legal entity subject to compliance with said rule" (in this regard, Supreme Court Judgment of November 24, 2011, Rec 258/2009).

To the above, it should be added, following the judgment of January 23, 1998, partially transcribed in the Supreme Court Judgments of October 9, 2009, Rec 5285/2005, and of October 23, 2010, Rec 1067/2006, that "although the culpability of the conduct must also be subject to proof, it must be considered, in order to assume the corresponding burden, that ordinarily the volitional and cognitive elements necessary to assess it are part of the the proven typical conduct, and its exclusion requires proof of the absence of such elements, or, in its normative aspect, that the due diligence required by the party claiming their absence has been exercised; In short, the invocation of the absence of fault is not sufficient to exonerate the data subject from typically unlawful conduct."

Consequently, the lack of fault is dismissed. Ultimate responsibility for the processing remains with the controller, who is the one who determines the existence of the processing and its purpose. It should be recalled that, as a general rule, operators process their customers' data under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the execution of a contract to which the data subject is a party (...). In this regard, DIGI has a network of approved retailers, points of sale, and distributors through a distribution contract to offer DIGI services. Among these services offered through its points of sale is the production of card duplicates. SIM cards
corresponding to a mobile telephone line.

Regarding the breach of the principle of proportionality, the GDPR expressly provides for the possibility of scaling up, by establishing fines that can be adjusted, taking into account a series of circumstances in each individual case.

Regarding the imposition of a warning, reprimand, or the adoption of corrective measures pursuant to Article 58 of the GDPR, a deterrent fine is one that has a genuine deterrent effect. In this regard, the judgment of the CJEU of June 13, 2013, Versalis Spa v Commission, C-511/11, ECLI:EU:C:2013:386, states:

“94. With regard, first of all, to the reference to the aforementioned Showa Denko v Commission judgment, it should be noted that Versalis misinterprets it. Indeed, the Court of Justice, in stating in paragraph 23 of that judgment that the deterrent factor is assessed by taking into account a multitude of elements and not just the particular situation of the undertaking in question, was referring to points 53 to 55 of the Opinion presented in that case by Advocate General Geelhoed, who had essentially stated that the deterrent factor may be intended not only to provide "general deterrence," defined as an action to discourage all undertakings in general from committing the infringement in question, but also to provide "specific deterrence," consisting of discouraging the specific defendant from violating the rules again in the future.Therefore, in that judgment, the Court of Justice merely confirmed that the Commission was not required to limit its assessment to factors relating solely to the specific situation of the undertaking in question.

“102. According to settled case-law, the objective of the deterrent multiplier factor and of taking into account, in this context, the size and overall resources of the undertaking in question lies in the desired impact on the undertaking in question, since the penalty must not be insignificant, particularly in relation to the undertaking's financial capacity (to that effect, see, in particular, Case C-413/08 P Lafarge v Commission [2010] ECR I-5361, paragraph 104, and the order of 7 February 2012 in Case C-421/11 P Total and Elf Aquitaine v Commission, paragraph 82).

We must address the unique circumstances of the claim presented, through which it can be seen that, from the moment the impersonator replaces the SIM, the victim's phone is left without service, transferring control of the line to the impersonators. Consequently, their powers of disposal and control over their personal data are affected, which

constitute part of the fundamental right to data protection, as stated by the Constitutional Court in Ruling 292/2000, of November 30, 2000 (FJ 7). Thus, by obtaining a duplicate SIM card, under certain circumstances, access is made possible to contacts or to applications and services that have the password recovery procedure of sending an SMS with a code to change passwords. In short, they will be able to impersonate those affected, being able to access and control, for example, email accounts. electronic; bank accounts; applications such as
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/20

WhatsApp; social networks such as Facebook or Twitter, and many more. In short, once the password is changed by the impersonators, they lose control of their accounts, applications, and services, which poses a major threat.

Ultimately, it is the data controller who has the obligation to integrate the necessary safeguards into the processing, in order to, pursuant to the principle of proactive accountability, comply and be able to demonstrate compliance, while respecting the fundamental right to data protection.

In any case, the operator must be able to prove that the data processing carried out complies with the principle of lawfulness.

Well, the result was that the defendant issued the SIM card at the request of a third party who was not the line owner and delivered it to This.

However, DIGI fails to prove compliance with the provisions of Article 6 of the GDPR.

Not even the respondent has been able to prove that, in this case, the procedure it implemented itself was followed, calling into question the diligence employed by the respondent to identify the person who requested a duplicate SIM card.

Digi requests that the following mitigating circumstances be considered:

(I) "At no time were special categories of data processed" (Article 83.2 g).

(II) "The degree of cooperation between DIGI and the AEPD" (Article 83.2 f) GDPR)

(III) "The absence of benefits obtained through the infringement," Article 83.2 k) of the GDPR and Article 76.2 c) of the LOPDGDD.

None of the mitigating circumstances invoked are admissible.

On the application of Article 83.2 g) of the GDPR, it should be noted that the European Data Protection Board's Guidelines 04/2022 on the calculation of administrative fines under the GDPR, version 2.1, adopted on May 24, 2023, state that: "Regarding the requirement to take into account the categories of personal data concerned (Article 83, paragraph 2, letter g) of the GDPR), the GDPR clearly highlights the types of data that merit special protection and, therefore, a stricter response in terms of fines."

From the above, we can conclude that not processing special categories of data does not constitute an extenuating circumstance; in any case, it would be a neutral circumstance.

Article 83.2.f) of the GDPR refers to the "degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the possible adverse effects of the infringement."

The respondent relies on the response to the requests of the Inspection Subdirectorate of this authority to consider that the aforementioned circumstance exists.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 18/20

However, this cannot be considered voluntary cooperation that actively seeks to mitigate the impact of the infringement, but rather falls within their legal obligation to respond to requests from the supervisory authority.

According to the GDPR, data controllers are obliged to comply with requests information and to provide the documentation required by the supervisory authorities. This obligation is an inherent part of their responsibility and does not, in itself, constitute collaboration to remedy or mitigate the effects of an infringement.

Regarding the application of Article 76.2.c) of the LOPDGDD, in conjunction with Article 83.2.k), the lack of benefits obtained, it should be noted that such a circumstance can only operate as an aggravating factor and in no case as a mitigating factor.

Article 83.2.k) of the GDPR refers to "any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement." And Article 76.2c) of the LOPDGDD states that "2. Pursuant to Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account: [...] c) Benefits obtained as a result of committing the infringement." Both provisions
mention as a factor that can be taken into account in the grading of the sanction

the "benefits" obtained, but not the "absence" of these, which is what DIGI alleges.

Furthermore, according to Article 83.1 of the GDPR, the imposition of fines is governed by the following principles: they must be individualized for each particular case, be effective, proportionate, and dissuasive. Accepting that the absence of benefits operates as a mitigating factor is contrary to the spirit of Article 83.1 of the GDPR and the principles that govern the determination of the amount of the fine. If, following the commission of a GDPR violation, the absence of benefits is considered a mitigating factor, the deterrent purpose served by the sanction is partially nullified. Accepting DIGI's argument in a case such as the one at hand would mean introducing an artificial reduction in the sanction. truly

should prevail; that resulting from considering the circumstances of Article 83.2 GDPR, which must be assessed.

The AEPD does not disassociate itself from any reasoning, nor does it attribute all responsibility to DIGI. It accuses it of the responsibility that corresponds to it as the controller of this specific processing "Issuance of a duplicate SIM card,"

since, according to the definition in Article 4.7 of the GDPR, it is the entity that determines the
purpose and means of the processing carried out.

As an operator, DIGI should be more demanding when providing a duplicate SIM card. Identity verifications must be exhaustive to avoid identity theft problems.

Therefore, having analyzed the allegations made in this optional appeal for reconsideration, it is found that no new legal arguments have been provided that would allow reconsideration of the meaning of the sanctioning resolution issued on November 8, 2018. 2024.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 19/20

III
Conclusion

Consequently, in this appeal for reconsideration, the appellant has not provided new facts or legal arguments that would allow reconsideration of the validity of the contested resolution.

IV
Late Resolution

Due to operational reasons of the administrative body, and therefore not attributable to the appellant, to date, this Agency has not issued the required ruling on this appeal.

In accordance with the provisions of Article 24 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (LPACAP), the meaning of administrative silence in procedures for challenging acts and provisions is dismissive.

However, and despite the time Once this period has elapsed, the Administration is required to issue an express resolution and notify it in all proceedings, regardless of their method of initiation, as provided in Article 21.1 of the aforementioned LPACAP.

Therefore, it is appropriate to issue the resolution that concludes the appeal for reconsideration procedure.

Having seen the aforementioned provisions and other generally applicable provisions,
the Presidency of the Spanish Data Protection Agency RESOLVES:

FIRST: TO DISMISS the appeal for reconsideration filed by DIGI SPAIN TELECOM, S.L.U. against the resolution of this Spanish Data Protection Agency issued on November 8, 2024, in file EXP202311911.

SECOND: TO NOTIFY DIGI SPAIN TELECOM, S.L.U. of this resolution.

THIRD: Warn the sanctioned party that the imposed sanction must be paid

once this resolution has been notified, in accordance with the provisions of
Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations, within the voluntary payment period established in
Article 68 of the General Collection Regulations, approved by Royal Decree
939/2005, of July 29, in conjunction with Article 62 of Law 58/2003, of December 17, by depositing it into restricted account no. ES00 0000 0000 0000 0000
0000, opened in the name of the Spanish Data Protection Agency at Banco
CAIXABANK, S.A. Otherwise, the payment will be made during the enforcement period.

If the notification date falls between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it falls between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second month or the next business day after.

In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Organic Law on Tax and Customs), this Resolution will be made public once it has been notified to the interested parties.

Against this resolution, which ends the administrative process pursuant to Art. 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (LPACAP), interested parties may file an administrative appeal before the Administrative Litigation Division of the National Court, in accordance with the provisions of Article 25 and section 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the aforementioned Law.

Finally, it is noted that, pursuant to the provisions of Art. 90.3 a) Under the LPACAP, the final administrative decision may be provisionally suspended if the interested party expresses their intention to file an administrative appeal. If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of the aforementioned LPACAP. They must also forward to the Agency the documentation proving the effective filing of the administrative appeal. If the Agency is not aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the provisional suspension. 180-020125
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es
  1. SAN 7/10/2007 (rec. 63/2006)