AEPD (Spain) - EXP202312279
| AEPD - EXP202312279 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 6(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 18.07.2023 |
| Decided: | 16.04.2025 |
| Published: | 28.10.2025 |
| Fine: | 200,000 EUR |
| Parties: | DIGI Spain Telecom, S.L. |
| National Case Number/Name: | EXP202312279 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | ricardo |
The DPA fined a telecommunications company €200,000 for duplicating a data subject's SIM card for a third person without the knowledge or consent of the data subject.
English Summary
Facts
In July 2023, a data subject filed a complaint with the DPA against DIGI Spain Telecom, S.L. (a telecommunications company, the controller). The data subject stated that, in October 2022, they were the holder of a mobile line with the controller. A distributor of the controller issued a duplicate SIM card to a third party without the data subject’s authorization, using a falsified identity document.
The fraudster, with the duplicate SIM, accessed confidential data and carried out several bank transfers, withdrawing a significant amount of money. The controller later confirmed to the data subject that the duplicate had been processed with a manipulated ID card.
Holding
The DPA found a violation of Article 6(1) GDPR. The DPA stated that the controller could not rely on any legal basis (in particular consent), because it duplicated the data subject's SIM card for a third party without the knowledge or consent of the data subject. The DPA emphasized that telecom operators must adopt robust identity verification protocols, especially for high-risk operations like SIM duplication, as the failure directly exposed the complainant to identity theft and financial fraud.
The DPA fined the controller €200,000, and considered it a serious infringement of the GDPR. The DPA noted that the situation exposed the data subject to identity theft and fraud. The DPA also highlighted the particularly sensitive nature of ID data, as it identifies the data subject beyond doubt, and can easily be used to commit identity theft.
Comment
The controller filed an internal appeal with the DPA on 21 May 2025. The DPA dismissed the appeal on the grounds that the controller had not presented any new facts or legal arguments.
This case is part of a growing trend of SIM-swap fraud cases in Spain and across the EU. The DPA’s reasoning aligns with previous decisions stressing the heightened duty of telecom operators to secure identity verification processes. The resolution highlights that even if distributors carry out the procedure, the responsibility for ensuring GDPR compliance remains with the telecom operator.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/36
File No.: EXP202312279
SANCTIONING PROCEDURE RESOLUTION
From the procedure initiated by the Spanish Data Protection Agency and based
on the following:
BACKGROUND
FIRST: Mr. A.A.A. (hereinafter, the complainant) filed a complaint with the Spanish Data Protection Agency on July 18, 2023.
The complaint is filed against DIGI SPAIN TELECOM, S.L. with NIF B84919760 (hereinafter, the respondent or DIGI). The grounds for the claim are as follows:
The complainant states that, in October 2022, they were the holders of a mobile phone line ***TELÉFONO.1 contracted with the telephone operator DIGI and that, on October 16, 2022, a third party was provided with a duplicate SIM card for the aforementioned line at a distribution establishment owned by the respondent, without their authorization. The complainant adds that the third party used a non-original ID card.
They add that with the duplicate SIM card, the third party had access to confidential data such as address books, contact numbers, and messages, thus facilitating identity theft, which led to access to their banking information. The claimant claims that this allowed the phisher, using the duplicate SIM card, to make seventeen bank transfers between October 16, 17, and
18, 2022, and three Bizum transfers, subtracting a total of ***AMOUNT.1 euros.
The claimant states that the operator did not verify the identity of the person who duplicated the SIM card, resulting in the illegal subtraction of the aforementioned amounts.
And, along with their written submission, the complainant provides the following relevant documentation:
-DIGI postpaid service contract dated August 4, 2021.
-Invoices issued by DIGI.
-Complaint filed by the complainant with DIGI and the latter's response.
In one of the emails sent by DIGI to the complainant regarding their claim, dated October 27, 2022, the entity confirmed that the third party to whom the complainant's duplicate SIM card was delivered used a
tampered ID. The same email identifies the distributor through which the duplicate card was processed, with an address in Tarragona.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 2/36
-Report to the National Police ***REPORT.1 Unit ***CITY.1 dated October 19, 2022.
SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), this complaint was forwarded to the respondent so that they could analyze it and inform this Agency within one month of the actions taken to comply with the requirements set forth in the data protection regulations.
The transfer, which was carried out in accordance with the regulations established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), was recorded electronically on September 25, 2023, as recorded in the acknowledgment of receipt in the file.
On October 25, 2023, DIGI requested an extension of the deadline for its response, which was granted.
On November 27, 2023, this Agency received a written response from the respondent, stating that: "The only ways DIGI makes available for its individual customers to request a duplicate SIM card are exclusively in person. The procedure can be carried out:
- Through our own physical stores, where the applicant must identify themselves in person with an original ID.
- Through our distributors (Dealers), where the applicant must identify themselves in person with an original ID.
1) On October 15, 2022, an individual who identifies himself as the complainant (in fact, he is the holder of an ID card with the complainant's information) appears before our distributor
***DISTRIBUTOR.1 and requests a duplicate SIM card for the line ***TELÉFONO.1.
2) In accordance with the established procedure, (…).
3) On October 16th at 10:30 a.m., the duplicate was validated by the Backoffice department and, in accordance with the security protocol, automatic notifications were sent to the contact phone number for the request and to the email address that was historically registered to communicate with the owner.
4) On the same day, the 16th, DIGI's Customer Service received two calls from a person who again identified himself as the complainant, regarding a technical problem due to which he had no line. According to the complainant's own statement in the complaint filed in the file, the origin was related to the technical problems that led to the repair of the mobile phone by the complainant in July of the same year.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 3/36
5) On the morning of On October 17th, a request for a duplicate SIM card was received from a person identifying themselves as the claimant, presenting their ID to our distributor ***DISTRIBUTOR.2. We attach the front of the ID card provided.
6th) On the same day, the 17th, the duplicate card was validated by the Backoffice department and, in accordance with the security protocol, automatic notifications were sent to the contact phone number for the request and to the email address that was historically registered to communicate with the cardholder.
7th) A few hours later on the same day, the 17th, a new request for a duplicate SIM card was received, submitted by a person identifying themselves as the claimant, to distributor ***DISTRIBUTOR.1, who provided the same documentation provided in point 2 for identification.
8th) On the same day, the 17th, the duplicate card was validated by the Backoffice department and, in accordance with the security protocol, it was sent. Automatic notifications were sent to the contact phone number for the request and to the email address that was historically registered to communicate with the account holder.
9) A few hours later, the claimant contacts DIGI by phone and
reports that they are experiencing the same problem with the line not working again.
After checking by the DIGI advisor (including making a hidden call to verify that the line has a signal), it is identified that the cause may be a duplicate SIM card.
10) On the 17th, a new request for a duplicate SIM card was received from a person who identified themselves as the claimant by showing their ID at our distributor ***DISTRIBUTOR.2. The documentation provided is the same as in
point 5).
11) On October 18, the duplicate card was validated by the Backoffice department and, in accordance with the security protocol, automatic notifications were sent to The contact phone number for the request and the email address that was historically registered to communicate with the account holder.
12) On the afternoon of the 18th, a person identifying themselves as the complainant
contacted us to address various technical issues and to inform us that they had suffered
a bank fraud in which money had been stolen from their bank account.
The complainant was advised to file the corresponding report, and a ticket was opened for possible fraud with code ***NUMBER.1.
The customer also requested that the number be registered again.
At the time of the events, a new SIM duplication procedure was in operation based on (…).
Given that the causes of the situation stem from (…):
1) (…).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 4/36
2) (…)”.
THIRD: On October 18, 2023, in accordance with Article 65 of the
LOPDGDD, the claim filed by the complainant was admitted for processing.
FOURTH: According to the report collected from the AXESOR tool, the entity
DIGI SPAIN TELECOM, S.L. It is a large company established in 2006, with a turnover of €644,000,000 in 2023.
FIFTH: On May 16, 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanctioning proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 6.1 of the GDPR, classified as Article 83.5.a) of the GDPR.
SIXTH: After notification of the aforementioned initiation agreement in accordance with the rules established in
Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), the respondent submitted a written statement of allegations on June 3, 2024, in which, in summary, the respondent begins
its defense by reiterating the arguments presented in previous allegations, which,
in its opinion, have not been refuted by the AEPD. It considers that its arguments remain
valid and requests that they be taken into account. It clarifies that, in this written statement, it will emphasize those points it considers most crucial to dismantle the
grounds on which the AEPD seeks to justify the sanction.
First allegation: Account and analysis of the alleged facts.
The defense proceeds with a detailed chronological description of the events, situating the
incident in relation to identity theft that allowed a third party to
fraudulently obtain a duplicate of the claimant's SIM card. It states that
the process was carried out in person on several occasions, and the claimant's
National Identity Document was always presented.
It also asserts that it has robust security procedures for the
issuance of SIM duplicates, such as in-person verification of the DNI and manual validation
of the documents by the BackOffice department. However, it maintains
that the phisher used a falsified DNI, which allowed the security measures to be overcome.
Therefore, in its opinion, the phisher already had the claimant's personal data
before contacting the company, and that this facilitated obtaining the duplicate.
Second allegation: Security protocol and measures adopted.
The respondent emphasizes that, given the situation, all current security measures were applied. Among these, the identity verification procedure stands out,
which requires the physical presentation of the DNI (National Identity Document) and its subsequent manual validation. After the incident, it claims to have reinforced these measures by introducing new measures,
such as double verification by phone and in person.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/36
Furthermore, it confirms the existence of a contingency plan that allowed it to act quickly to mitigate the effects of the identity theft, ensuring that the complainant
regained control of their line. It mentions that, despite its efforts to continuously improve its protocols,
there is no completely foolproof security system and that the identity theft committed was sophisticated enough to deceive the agents in charge of validation.
Third argument: Legality of processing personal data.
The defense insists that the company has not illegally processed the claimant's personal data, since the data was already in the hands of the impersonator before the latter requested the duplicate SIM card. In this regard, it is mentioned that the telephone number (MSISDN) and the IMSI are technical data that, in and of themselves, do not allow the owner to be identified without access to the company's internal systems.
Reference is made to the ruling of the National Court of September 17, 2008 (appeal number 353/2007). In its opinion, according to this ruling, the telephone number can only be considered personal data if the owner can be identified from that number, which it claims has not been proven in this case. It also cites the Supreme Court ruling of June 18, 2020 (Appeal 1074/2019,
Ruling No. 815/2020), which reinforces the interpretation that personal data does not automatically include a telephone number if it is not associated with a directly identified person.
Fourth allegation: Compliance with the protocol.
The respondent argues that it complied with all established security protocols, and the AEPD has failed to prove that the company breached its own security procedures. On the contrary, it considers that the AEPD has reached erroneous conclusions by considering that the mere fact that impersonation occurred indicates a lack of due diligence on the part of the company.
In this regard, it cites as a precedent the AEPD's decision to close case E/05168/2021, according to which the AEPD concluded that the breach of security measures by a third party does not necessarily imply that these measures are inadequate. It asserts that, in that case, despite the fact that unauthorized access to personal data occurred, the AEPD decided not to impose any sanctions because the company had exercised a sufficient level of due diligence.
Fifth argument: Inadmissibility of strict liability.
The defense rejects any attempt by the AEPD to impose strict liability, that is, to sanction the company simply for the outcome of the incident, without demonstrating fault or negligence. The respondent argues that, pursuant to Constitutional Court Ruling No.
76/1990, the principle of culpability requires the existence of intent or negligence, and the mere existence of an error does not justify the imposition of a sanction.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 6/36
Furthermore, the National Court Ruling of February 25, 2010, is cited, according to which the breach of security measures by organized third parties is not sufficient grounds to sanction the affected company, especially when adequate protective measures have been implemented.
Sixth allegation: Disproportionality of the sanction.
Regarding the sanction, the respondent argues that it is disproportionate in relation to the facts, as no intent or gross negligence in its actions has been demonstrated. In support of this claim, the Court cites Supreme Court Ruling 543/2022 of February 15, which establishes that the obligations imposed on companies regarding data security are not obligations of results, but of means. It maintains that the company is only obliged to implement appropriate measures to mitigate risks, but cannot guarantee that incidents like the one that occurred will not occur.
It also highlights that the AEPD has imposed less severe sanctions in similar cases. Specifically, it compares this case with case PS/000027/2021, in which the AEPD sanctioned another telecommunications operator (XFERA MÓVILES, S.A.) with a fine of €200,000 for several cases of identity theft through the use of duplicate SIM cards. The Court states that, despite the fact that the situation was similar, the penalty imposed on the respondent in this case
is proportionally much higher, which it considers unjustified.
Furthermore, it points out that, in accordance with Article 83.2 of the GDPR and
Article 76.2 of the LOPDGDD, the following mitigating circumstances exist in this case, which have not been considered in the appropriate grading of the penalty:
The respondent effectively resolved the incident that was the subject of the complaint (Article 83.2 c);
At no time were special categories of data processed (Article 83.2 g of the GDPR).
The degree of cooperation between DIGI and the AEPD to remedy an alleged infringement and mitigate its potential adverse effects: it has been proven that all requests for information
requested by this Agency have been responded to in a timely manner. Furthermore, DIGI provided, in the first request for information, prior to being requested by the AEPD, all the contractual and supporting documentation related to this situation, of its own volition, expressly stating its good faith and intention to cooperate with the authority (Art. 83.2 f) GDPR).
The non-existent benefit obtained by DIGI as a result of the data processing involved in this procedure. In any case, DIGI has been harmed, as
already noted, by being affected by the commission of fraud by a third party, which has forced it to remedy the situation and conduct investigations, with the consequent associated costs (Art. 83.2 k) 24 GDPR). It should be noted that not only does this not entail a financial benefit, but DIGI has been harmed by the error
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 7/36
committed by its supplier, despite having taken all necessary measures and
guarantees.
For all the above reasons, the quantification of the possible sanction to be imposed on DIGI in relation to the alleged breach of the obligations of Article 6.1 of the GDPR indicates that it should be limited to a warning and, ultimately, the proposal included in the Initiation Agreement notified to DIGI should be moderated or modified, taking into account its arguments.
SEVENTH: On November 22, 2024, a resolution proposal was made, proposing that the Director of the Spanish Data Protection Agency sanction DIGI SPAIN TELECOM, S.L., with Tax ID No. B84919760, for a violation of Article 6.1 of the GDPR, classified in Article 83.5 a) of the GDPR, with a fine of €200,000 (two hundred thousand euros).
EIGHTH: After notification of the resolution proposal on November 25, 2024, the respondent requested a copy of the file and an extension of the deadline granted to it and submitted a written statement of allegations on December 17, 2024, which, in summary, reiterates the allegations previously submitted.
First statement: Regarding the alleged facts and supporting documentation.
DIGI insists that the current identity thief knew and had under his control, prior to any contact with DIGI, an ID card containing the complainant's personal information.
This documentation, obtained prior to contacting DIGI, is what enabled him to obtain the SIM duplicates.
It states that DIGI did not illegitimately process the data for three reasons:
- DIGI acted diligently, in compliance with the procedure established for this purpose, responding to the request of the applicant, who identifies himself as a DIGI customer.
- The alleged undesired effects are caused by the actions of a
third party (alleged fraudster), who had the data and ID of the
complainant.
- DIGI has not provided any of the interested party's personal data,
since the codes (including those on the SIM card) would not, per se,
be classified as personal data.
Second allegation: Regarding "SIM SWAPPING" and the resulting
responsibilities
It states that the commission of this type of fraud stems from an initial breach of
the confidentiality of the interested party's personal data with their financial institution,
usually through "phishing" to obtain their
banking credentials.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/36
Furthermore, it notes that the report issued by the European Union Cybersecurity Agency confirms that, to carry out a fraudulent SIM duplication, the fraudster
needs access to some of the victim's personal data, a customer of the operator.
This means that cybercriminals have access to their victims' personal data before contacting the Mobile Network Operator.
It points out that this is what happened in the present case: the victim lost control
over their personal data and identity documents to the impersonator
before the latter contacted DIGI. In other words, it is through the "phishing" attack that the victim loses control over their personal data, and it is this fact that triggers and enables the fraud.
Third allegation: Regarding the failure to assess the evidence.
The respondent maintains that it has listed in its letters to the AEPD the
measures regarding the procedures for obtaining SIM card duplicates,
however, the AEPD has not assessed these measures.
Furthermore, it indicates that, despite the commission of an undesirable result, the Agency
must evaluate the procedure established for this purpose, as well as its review and
implementation of improvements.
Fourth allegation: Regarding the failure to prove fault or negligence on the part of DIGI.
The respondent insists that, despite the commission of an undesirable result, the
Agency must evaluate the procedure established for this purpose, as well as its review and
implementation of improvements.
Thus, DIGI's diligence has been demonstrated prior to the event, with the establishment of
protocols and measures at the time the acts were committed by
following its identification process, and subsequently, with the improvement of the protocols
and the reversal of the situation that have already been provided in this case.
DIGI carried out an adequate and valid identity verification process, by
using supporting documentation and in-person verification, although it is not possible
to impose on DIGI the ability to detect advanced forgeries,
which are invaluable even for an airport or law enforcement agencies.
Fifth argument: Regarding the inadmissibility of strict liability.
It considers that the Proposal is not in accordance with the law, as it imposes on DIGI an
obligation of results, consisting of the establishment of infallible measures to address risks imposed by third parties who, unilaterally, have decided to outsource, without DIGI's consent, their own security obligations as data controllers. It even alleges a violation of Article 6.1 of the GDPR based solely on the harmful result produced by the fraudulent intervention of a third party that overcomes security measures, without taking into account the due diligence used, and without considering the deployment of technically appropriate measures implemented for processing for which DIGI does not decide either the purpose or the means.
Sixth allegation: Regarding the lack of defense and legal certainty.
The respondent points out that it cannot foresee or know what the applicable duty of care is, as the AEPD requires the achievement of a result and zero risk.
Seventh allegation: Regarding the lack of proportionality of the proposed sanction
In this regard, the respondent disagrees with the aggravating factors applied:
The intentionality or negligence of the violation (Article 83.2 b) of the GDPR).
It points out that, given that the incident was caused by the commission of a criminal act by a third party not attributable to DIGI, it does not seem permissible to attribute this aggravating factor to DIGI.
Any prior violation committed by the controller or processor.
It states that the general classification of this type of crime, such as SIM Swapping, should not be confused with the existence of a common modus operandi or type of crime among all of them. It is not possible to demand absolute effectiveness of the measures designed to prevent fraud, since it is impossible to predict, even if extensive resources are dedicated to it, what the next possible activity will be that will require a new deployment of measures by DIGI.
The connection between its activity and the processing of personal data of clients or third parties (Article 83.2K of the GDPR in relation to Article 76.2 b of the LOPDGDD).
It points out that this aggravating factor must be put in context with the deployment of measures carried out by DIGI. In this sense, it indicates that the data processing does not arise from the entity's intention, but rather the commission of a crime in which DIGI is the injured party. For all these reasons, this aspect cannot be construed as an
aggravating factor.
Regarding the mitigating factors not applied by the Agency when assessing the sanction, the respondent believes that the following should be taken into consideration:
- At no time were special categories of data processed (Art. 83.2 g of the GDPR).
The respondent states that DIGI has not processed special category data, and that the
name, surname, and ID number are not part of the special categories (Art. 9 of the GDPR).
- The degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate its potential adverse effects.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 10/36
Likewise, it notes that it has responded in a timely manner to all requests for information requested by this Agency (Art. 83.2 f of the GDPR).
- The nonexistent benefit obtained.
Furthermore, it states that it has been harmed by the commission of fraud by a third party, which has forced it to remedy the situation and conduct investigations, with the associated consequences (Article 83.2k GDPR).
For all the above, the respondent requests that a resolution be issued indicating the closing of the procedure or, alternatively, terminating the procedure by issuing a warning and, ultimately, if it considers the imposition of a sanction appropriate, easing or modulating the sanction.
Based on the actions taken in this procedure and the documentation in the file, the following have been established:
PROVEN FACTS
FIRST. – DIGI confirms the following in the statements made in the
response letter to this Agency dated November 27, 2023:
1) The complaining party is the owner of the DIGI mobile line ***TELÉFONO.1, with address at ***CITY.1. A third party appears on October 15, 2022,
before DIGI's distributor ***DISTRIBUIDOR.1 in the city of Tarragona,
an individual who identifies himself as the complainant, carrying a DNI (National Identity Document) with the complainant's information, and requests a duplicate SIM card for the line ***TELÉFONO.1. The aforementioned distributor keeps a copy of the copy to send to the backoffice service for validation of the duplicate, which is then validated by DIGI.
2) On October 16, 2022, the complainant contacted DIGI Customer Service to report that they had no line. The next day, the complainant went to a point of sale in ***LOCATION.1 and requested a duplicate SIM card.
3) On the following day, October 17, a third party went to the same point of sale in Tarragona (***DISTRIBUTOR.1) and again obtained a duplicate SIM card.
4) A few hours later on the 17th, the complainant contacted DIGI by phone and reported that they were experiencing the same problem with their line not working.
5) On the same day, the complainant went to the same point of sale in ***LOCATION.1 and requested another duplicate SIM card (the fourth for the same line in three days).
6) On October 18, 2022, the claimant notified DIGI that he had suffered a
bank fraud (almost ***AMOUNT.2 euros).
SECOND. – The file shows that at the time of the events, DIGI had a security procedure in place, based on (…).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 11/36
THIRD. – The screenshots provided by DIGI on June 3, 2024, show the applicant's identity verification process applied
to the present case, in force at the time of the events, to obtain a duplicate SIM card, which was as follows:
(…).
(…).
(…).
FOURTH. – DIGI acknowledges in its response to this Agency dated November 17, 2023: “(…):
1st) (…).
2nd) (…)”.
LEGAL BASIS
I
Jurisdiction
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the Guarantee of Digital Rights (hereinafter LOPDGDD), the President of the Spanish Data Protection Agency is competent to initiate and resolve this procedure.
Likewise, Article 63.2 of the LOPDGDD establishes that: "The procedures processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the regulatory provisions issued in its development and, insofar as they do not contradict them, in a subsidiary manner, by the general rules on administrative procedures."
II
Preliminary Questions
Article 4.1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ("the data subject"); an identifiable natural person shall be any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 12/36
Article 4.2 of the GDPR defines "processing" as: any
operation or set of operations performed on personal data or sets of personal data,
whether or not by automated means, such as
collection, recording, organization, structuring, storage, adaptation or
alteration, retrieval, consultation, use, disclosure by transmission, dissemination or
any other form of making available, alignment or combination, restriction,
erasure or destruction;
Furthermore, Article 4.7 of the GDPR establishes that the "controller" or
"controller" is: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; If
Union or Member State law determines the purposes and means of processing,
the controller or the specific criteria for its appointment may be established by Union or Member State law.
A SIM card is a smart card containing a chip that stores
the customer's mobile telephone line number and personal identification number, but which may also provide other types of data, such as information
on the telephone directory or calls and messages. Therefore, for the purposes of
Articles 4.1 and 4.2 of the GDPR, the issuance of duplicate SIM cards constitutes the processing of personal data.
DIGI carries out this activity in its capacity as data controller, since it
determines the purposes and means of such activity, pursuant to Article 4.7 of the
GDPR.
III
Response to the allegations regarding the Initiation Agreement
In response to the allegations presented by the respondent entity, the following should be noted:
First and Second Allegations: Security Protocol and Measures Adopted.
In its defense, DIGI refers to the set of security measures it has adopted, stating that the measures implemented are the minimum required of any organization with the characteristics and in the context in which a telecommunications operator operates.
As proven, the respondent party has breached its own security policy. DIGI acknowledges in its response to this Agency dated November 17, 2023: "(…):
1st) (…).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 13/36
2nd) (…)".
In this regard, it should be noted that the fact that we are dealing with third-party fraud makes it necessary to ensure that the person to whom the duplicate SIM card is issued is who they claim to be, and appropriate preventive measures must be taken to verify the identity of a person whose data will be processed, as recognized in the Seventh Legal Basis of the San, SCA, of May 5, 2021 ("On the other hand, regarding the fact that we are dealing with third-party fraud, as we stated in the San
of October 3, 2013 (Rec. 54/2012): "Precisely for this reason, it is necessary to ensure that the person contracting is who they claim to be, and appropriate preventive measures must be taken to verify the identity of a person whose personal data will be processed...").
Throughout this procedure, DIGI has repeatedly stated that The fraudulent card duplications occurred after the fraudsters had bypassed their security policy. It is considered inevitable that, despite the existence of the security policy, there may be cases in which, through certain mechanisms, said security policy may be fraudulently bypassed, without any blame being placed on DIGI.
However, the mere existence of a security policy cannot justify a violation of the principle of lawfulness provided for in Article 6.1 of the GDPR. In addition to existing measures, these measures must be effective, and the data controller must ensure that they are strictly complied with at all times. Otherwise, the measures adopted fail to fulfill their purpose and may lead to unlawful processing, as is the case here.
Therefore, the issue here lies not in the level of sophistication of the third party's criminal attack, but in the breach of the security measures that allowed the unlawful processing of personal data. The defendant cannot exonerate its liability by appealing to the existence of minimum measures when the failure lay in the application of those measures, allowing a violation of the lawfulness of the processing.
It should be noted in this regard that the issuance of a fraudulent duplicate SIM card for the complainant's mobile line occurred on two occasions, only one day apart. Added to this is (i) that between the two fraudulent duplicate SIM card issuances, one was issued by the complainant itself, motivated by the loss of service that the first fraudulent issue entailed; and (ii) that all three duplicates were issued in a physical store: the fraudulent ones at a point of sale in Tarragona, and the one requested by the complainant at a point of sale in ***LOCALIDAD.1, where it is domiciled. None of these circumstances were considered by DIGI when handling the requests made by the impersonator, who did not take any precautions or raise any alerts. would have
at least prevented the issuance of the second fraudulent duplicate.
DIGI has also claimed that its contingency plan ensured that the
complainant regained control of his line. However, according to the proven account of events
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/36
Digi did not take any measures for this purpose; rather, it was the
actions taken by the complainant that allowed him to recover the service
that was disabled when the fraudulent SIM card duplicates were issued. On each
occasion that the complainant lost service on his mobile line for that reason (twice on two consecutive days), he went to a point of sale in
***LOCATION.1 to recover said telephone service by delivering
new card duplicates, the issuance of which implied the cancellation of the issued fraudulently.
Third allegation: Lawfulness of processing personal data.
DIGI insists that the company has not illegally processed the complainant's personal data, since the data was already in the hands of the impersonator before the latter requested the duplicate SIM card. In this regard, it mentions that the telephone number (MSISDN) and the IMSI are technical data that, in and of themselves, do not allow the owner to be identified without access to the company's internal systems.
Reference is made to the ruling of the National Court of September 17, 2008 (appeal number 353/2007). In its opinion, according to this ruling, the telephone number can only be considered personal data if the owner can be identified from that number, which it claims has not been proven in this case. It also cites the ruling of the Supreme Court of June 18, 2020 (Appeal 1074/2019,
Judgment No. 815/2020), which reinforces the interpretation that personal data does not automatically include a telephone number if it is not associated with a directly identified person.
It can be inferred that DIGI provided a duplicate SIM card to a third party other than the legitimate owner of the mobile line, after the third party overrode the existing security policy, which demonstrates a breach of the duty to protect customer information.
Denying negligence on the part of DIGI would be equivalent to acknowledging that its conduct—by action or omission—was diligent. Obviously, we do not share this perspective of the facts, since the lack of due diligence has been proven. The SAN of October 17, 2007 (rec. 63/2006) is very illustrative, based on the fact that these are entities whose activity involves the continuous processing of customer data, stating that "...the Supreme Court has been understanding that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not behave with the required diligence. And in assessing the degree of diligence, the professionalism of the individual must be especially considered, and there is no doubt that, in the case now under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."
The case file establishes that adequate security has not been guaranteed in the processing of personal data, given the result of the identity theft. That is, a third party has gained access
to the personal data of the line owner.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 15/36
It should be noted that the SIM card is inserted inside the mobile terminal. It is a
small, physical smart card containing a chip that stores the subscriber's service key used to identify themselves to the network, that is, the customer's mobile telephone line number (MSISDN)
(Mobile Station Integrated Services Digital Network), as well as the subscriber's personal identification number (IMSI) (International Mobile Subscriber Identity). However, it can also provide other types of data, such as information on the phone book or calls and messages.
The issuance of a duplicate SIM card entails the processing of the holder's personal data, since any person whose identity can be determined, directly or indirectly, in particular by means of an identifier (Article 4.1 of the GDPR) is considered an identifiable natural person. The issuance of a duplicate SIM card necessarily involves the processing of personal data, since it is carried out on the line and identity of the holder. Therefore, the SIM card identifies a telephone number, and this number, in turn, identifies its holder. In this regard, the CJEU judgment in Case C-101/2001 (Lindqvist) of 6.11.2003, paragraph 24, ECR 2003 p. I-12971: "The concept
of 'personal data' used in Article 3(1) of Directive 95/46
in accordance with the definition in Article 2(a) of that Directive, includes 'any information relating to an identified or identifiable natural person'. This
concept undoubtedly includes a person's name together with their telephone number or
other information relating to their working conditions or hobbies."
In short, both the data processed to issue a duplicate SIM card and the
SIM (Subscriber Identity Module) card that unequivocally and uniquely identifies the subscriber on the network are personal data, and their processing must be
subject to data protection regulations.
Fourth argument: Compliance with the protocol.
The respondent maintains that it complied with all established security protocols, and the AEPD has failed to prove that the company breached its own security procedures. On the contrary, it considers that the AEPD has
reached erroneous conclusions by considering that the mere fact that identity theft occurred is indicative of a lack of due diligence on the part of the
company.
The respondent issued two SIM cards to a third party who was not the owner of the
line, and did not follow the verification procedure it had implemented.
DIGI fails to prove that the procedure it established was followed.
In fact, DIGI states in its response to this Agency's request for information dated November 17, 2023, that it was a human error on the part of
two back-office agents.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 16/36
Well, according to the identification procedure described by the respondent,
the two validating agents at DIGI's internal office did not verify the authenticity or compare the copy of the DNI received from the official distributor
with the original ID document on two occasions, on October 15 and 17, 2022. Thus, if this operation had been carried out correctly,
both duplicates would have been denied.
Based on the above, in the case analyzed, the
diligence employed by the respondent to verify the identity of the person
who requested a duplicate SIM card is called into question.
In this regard, it cites as a precedent the AEPD's resolution to close file E/05168/2021, according to which the AEPD concluded that the breach of security measures by a third party does not necessarily imply that these measures are inadequate. It asserts that, in that file, despite the fact that unauthorized access to personal data occurred, the AEPD decided not to impose any sanctions because the company had displayed a sufficient level of due diligence.
In that file, the circumstances were different. It involved a third party that was making a series of inquiries and requests regarding the data subject's line, because it had access to the complainant's personal information due to the relationship between them. That complaint was closed pursuant to the principle of presumption of innocence, which prevents the attribution of an administrative offense when no evidence or indications have been obtained that would indicate the existence of an offense. The
case now being resolved is different, in which the sanction is imposed for the data processing carried out by DIGI, which consisted of issuing a duplicate SIM card.
In any case, it should be clear that following the protocols established by DIGI for these procedures is not sufficient to justify the lawfulness of the processing under the GDPR, since these protocols do not satisfy the need for a legitimate basis. Furthermore, the identity verification procedure followed by DIGI has not adequately guaranteed compliance with the GDPR.
Fifth allegation: Inadmissibility of strict liability.
The defense rejects any attempt by the AEPD to impose strict liability, that is, to sanction the company simply for the
result of the incident, without demonstrating fault or negligence. The respondent
argues that, pursuant to Constitutional Court Ruling No.
76/1990, the principle of culpability requires the existence of intent or negligence, and the mere
existence of an error does not justify the imposition of a sanction.
Furthermore, the National Court Ruling of February 25, 2010, is cited,
according to which the override of security measures by organized third parties is not sufficient grounds for sanctioning the affected company,
especially when adequate protective measures have been implemented.
Regarding DIGI's liability, it should be noted that, in general, DIGI
processes its customers' data under the provisions of Article 6.1 b) of the GDPR,
as processing is considered necessary for the execution of a contract to which
the data subject is a party or for the application, at the request of the data subject, of pre-contractual measures.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/36
In other cases, it bases the lawfulness of the processing on the bases
provided for in Article 6.1.a), c), e), and f) of the GDPR.
Furthermore, to complete the scam, a third party must "impersonate" the data subject in order to receive the duplicate SIM card. This
a priori entails processing that violates the principle of legality, since a third party is processing data, having access to it, without any legal basis, in addition to the
violation of other principles such as confidentiality.
Certainly, the principle of liability provided for in Article 28 of the LRJSP (Law of Justice of the State),
stipulates that: "Only natural and legal persons, as well as, when a law recognizes their capacity to act, groups of affected parties, unions and entities without legal personality, and independent or autonomous assets, who are found to be responsible for such acts due to intent or negligence, may be sanctioned for acts constituting an administrative offense."
However, the method of attributing liability to legal persons does not correspond to the forms of intentional or reckless culpability that are attributable to human conduct. Thus, in the case of violations committed by legal entities, although the element of culpability must be present, it is necessarily applied differently than it is with respect to natural persons.
According to STC 246/1991, "(...) this different construction of the imputability of the authorship of the infringement to the legal entity arises from the very nature of the legal fiction to which these subjects respond. They lack the volitional element in the strict sense, but not the capacity to violate the rules to which they are subject.
Capacity to violate and, therefore, direct blameworthiness derives from the legal asset protected by the rule being violated and the need for such protection to be truly effective and the risk that, consequently, must be assumed by the legal entity that is subject to compliance with said rule" (in this sense, STS of November 24, 2011, Rec 258/2009).
To the above, it should be added, following the judgment of January 23, 1998, partially transcribed in the Supreme Court rulings of October 9, 2009, Rec 5285/2005, and of October 23, 2010, Rec 1067/2006, that "although the culpability of conduct must also be subject to proof, it must be considered, in order to assume the corresponding burden, that the volitional and cognitive elements necessary to assess such conduct ordinarily form part of the proven typical conduct, and that their exclusion requires proof of the absence of such elements, or, in its normative aspect, that the due diligence required by the party claiming their absence has been exercised; in short, invoking the absence of culpability is not sufficient to exonerate a person from typically unlawful conduct."
Consequently, the lack of culpability is dismissed. Ultimate responsibility for the processing remains with the data controller, who is the party responsible for determining the existence of the processing and its purpose. It should be recalled that, as a general rule, operators process their customers' data under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the execution of a contract to which the data subject is a party (…). In this regard, DIGI has a network of approved sales representatives, points of sale, and distributors through a distribution contract to offer DIGI services. Among these services offered through its points of sale is the production of duplicate SIM cards corresponding to a mobile phone line.
Sixth allegation: Disproportionality of the sanction.
Regarding the sanction, the respondent argues that it is disproportionate in relation to the facts, as no intent or gross negligence has been demonstrated. In support of this claim, it cites Supreme Court Ruling 543/2022, of February 15, which establishes that the obligations imposed on companies regarding data security are not obligations of results, but of means. It maintains that the company is only obligated to implement appropriate measures to mitigate risks, but cannot guarantee that incidents like the one that occurred will not occur.
It also highlights that the AEPD has imposed less severe sanctions in similar cases. Specifically, it compares this case with file PS/000027/2021, in which the AEPD sanctioned another telecommunications operator
(XFERA MÓVILES, S.A.) with a fine of €200,000 for several cases of
identity theft through the use of SIM card duplication. It states that, despite
the situation being similar, the fine imposed on the defendant in this case
is proportionally much higher, which it considers unjustified.
Regarding the breach of the principle of proportionality, the GDPR expressly provides
for the possibility of scaling, by establishing fines
that can be adjusted, depending on a series of circumstances in each individual case.
Regarding the imposition of a warning, reprimand, or the adoption of corrective measures pursuant to Article 58 of the GDPR, a deterrent fine is
one that has a genuine deterrent effect. In this regard, the judgment of the
CJEU of 13 June 2013, Versalis Spa v Commission, C-511/11, ECLI:EU:C:2013:386, states:
“94. With regard, first of all, to the reference to the aforementioned judgment in Showa Denko v Commission, it must be noted that Versalis misinterprets it. Indeed,
the Court of Justice, in stating in paragraph 23 of that judgment that the deterrent factor is assessed by taking into account a multitude of elements and not only the
particular situation of the undertaking concerned, was referring to points 53 to 55 of the Opinion presented in that case by Advocate General Geelhoed, who had essentially stated that the deterrent factor may be aimed not only at “general deterrence,” defined as an action
to not only discourage all companies, in general, from committing the infringement in question, but also a "specific deterrent," consisting of discouraging the specific defendant from violating the rules again in the future. Therefore, in that judgment, the Court of Justice only confirmed that the Commission was not required to limit its assessment to factors related solely to the particular situation of the company in question.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 19/36
situation of the company in question."
“102. According to settled case law, the objective of the deterrent multiplier factor and of the consideration, in this context, of the size and overall resources of the undertaking in question lies in the desired impact on the undertaking in question, since the penalty must not be insignificant, particularly in relation to the undertaking's financial capacity (to this effect, see, in particular, Case C-413/08 P Lafarge v Commission [2010] ECR I-5361, paragraph 104, and the order of 7 February 2012 in Case C-421/11 P Total and Elf Aquitaine v Commission, paragraph 82).”
We must address the unique circumstances of the claim presented, through which it can be established that, from the moment the impersonator
replaces the SIM, the victim's phone is left without service,
transferring control of the line to the impersonators. Consequently,
their powers of disposal and control over their personal data are affected, which
constitute part of the fundamental right to data protection,
as stated by the Constitutional Court in Ruling 292/2000, of November 30, 2000 (FJ 7). Thus, by obtaining a duplicate SIM card,
under certain circumstances, access is made possible to contacts or to
applications and services that have as a password recovery procedure the
sending of an SMS with a code to change passwords. In short,
they will be able to impersonate those affected, being able to access and control, for
example: email accounts; Bank accounts; applications such as
WhatsApp; social networks such as Facebook or Twitter, and many more. In short,
once the password is changed by the impersonators, they lose
control of their accounts, applications, and services, which poses a significant threat.
The sanctioning procedure PS/000027/2021, filed against the other operator, charged it with violating Article 5.1f. It does not accuse it of fraud or unlawful data processing, but rather a lack of guarantees regarding the security measures that result from transferring data to a third party.
In this sanctioning procedure, the sanction is imposed because DIGI provided a duplicate of the complainant's SIM card to a third party without its consent and without verifying the third party's identity. For this reason, Article 6.1 of the GDPR is charged.
Ultimately, it is the data controller who has the obligation to integrate the necessary safeguards into the processing, in order to, pursuant to the principle of proactive accountability, comply and be able to demonstrate compliance, while respecting the fundamental right to data protection.
Regarding the precedent invoked by DIGI, reported under number PS/00027/2021,
it should be noted that, unlike what occurred in the case that motivated the
actions, in that precedent, several mitigating circumstances were considered that do not exist in the present case, in which, moreover, the existence of several previous violations committed by DIGI, many of them for acts similar to those analyzed, is considered decisive
in establishing the fine.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 20/36
IV
Response to the allegations regarding the Proposed Resolution
In response to the allegations presented by the respondent entity, the following should be noted:
First and Second Allegations: Regarding the alleged facts and the supporting documentation in this regard and regarding "SIM SWAPPING and the resulting liabilities.
As proven, the respondent party has breached its own security policy. DIGI acknowledges in its response to this Agency dated November 17, 2023: "(…):
1st) (…).
2nd) (…)”.
In this regard, it should be noted that the fact that we are dealing with third-party fraud makes it necessary to ensure that the person to whom the duplicate SIM card is issued is who they really claim to be, and appropriate preventive measures must be taken to verify the identity of a person whose data will be processed, as recognized in the Seventh Legal Basis of the San, SCA, of May 5, 2021 (“On the other hand, regarding the fact that we are dealing with third-party fraud, as we stated in the San
of October 3, 2013 (Rec. 54/2012) -: "Precisely for this reason, it is necessary to ensure that the person who contracts is who they really claim to be, and appropriate preventive measures must be taken to verify the identity of a person whose personal data will be processed...").
Throughout this procedure, DIGI has repeatedly stated that the fraudulent card duplications occurred after the fraudsters had bypassed its security policy. It believes it is inevitable that, despite the existence of the security policy, there may be cases in which, through certain mechanisms, said security policy can be fraudulently bypassed, without any liability to DIGI.
However, the mere existence of a security policy cannot justify a violation of the principle of lawfulness provided for in Article 6.1 of the GDPR. In addition to existing measures, these measures must be effective, and the data controller must ensure that they are strictly adhered to at all times. Otherwise, the measures adopted fail to fulfill their purpose and may lead to unlawful processing, as is the case here.
Therefore, the issue here lies not in the level of sophistication of the third party's criminal attack, but in the breach of the security measures that allowed the unlawful processing of personal data. The respondent cannot exonerate its liability by invoking the existence of minimum measures when the failure lay in the application of those measures, allowing a violation of the lawfulness of the processing.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 21/36
It should be noted in this regard that the issuance of a fraudulent duplicate SIM card for the complainant's mobile line occurred on two occasions, only one day apart. Added to this is (i) that between the two fraudulent duplicate SIM card issuances, one was issued by the complainant itself, motivated by the loss of service that the first fraudulent issue entailed; and (ii) that the three duplicates were issued in a physical store, the fraudulent ones at a point of sale in Tarragona, and the one requested by the complainant at a point of sale in ***LOCALIDAD.1, where the complainant resides. None of these circumstances were considered by DIGI when handling the requests made by the impersonator, who did not take any precautions or establish any alerts that would have prevented at least the issuance of the second fraudulent duplicate.
DIGI has also claimed that its contingency plan ensured that the complainant regained control of his line. However, according to the proven facts, DIGI did not take any measures to that end; rather, it was the actions taken by the complainant that allowed him to recover the service that was disabled when the fraudulent duplicate SIM cards were issued. On each occasion that the complainant lost service on their mobile line for that reason (twice on two consecutive days), they went to a point of sale in
***LOCATION.1 to restore said telephone service by delivering
new duplicate cards, the issuance of which implied the cancellation of those issued fraudulently.
Third allegation: Regarding the failure to assess the evidence.
DIGI points out that it has been listing in its letters to the AEPD the measures regarding
the procedures for obtaining duplicate SIM cards; however,
the AEPD has not assessed these measures.
Furthermore, it indicates that despite the occurrence of an undesirable result, the Agency
must evaluate the procedure established for this purpose, as well as its review and
implementation of improvements.
Well, in the present case, the penalty is not for a lack of security measures but rather for non-compliance with said security policy. The respondent has breached its own security policy. DIGI acknowledges in its response to this Agency dated November 17, 2023: "(...):
1st) (...).
2nd) (...)".
In relation to the above, it should be noted that the fraudulent intervention of a third party has revealed a deficient risk analysis, as well as the insufficient implementation, review, and control of security measures by the operator.
A third party other than the data subject has exceeded the security measures established by DIGI. This shows that the identification of the data subject did not occur with sufficient guarantees, regardless of whether the identification was carried out by the data subject themselves or by a fraudulent third party.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 22/36
In short, a lack of appropriate security measures and a breach of the
obligations arising from proactive responsibility, especially when the "errors"
persist over time.
Fourth allegation: Regarding the failure to prove fault or negligence on the part of
DIGI.
The respondent argues that it complied with all established security protocols
and the AEPD has failed to prove that the company breached its
own security procedures. On the contrary, it considers that the AEPD has
reached erroneous conclusions by considering that the mere fact that
impersonation occurred is indicative of a lack of due diligence on the part of the
company.
It should be noted that the respondent issued two SIM cards to a third party who was not the line holder and did not follow the verification procedure it had implemented. Therefore, DIGI cannot prove that the procedure it had established was followed.
In fact, DIGI states in its response to this Agency's request for information dated November 17, 2023, that it was a human error on the part of two back-office agents.
In accordance with the identification procedure described by the respondent, the two validating agents in DIGI's internal office did not verify the authenticity of the copy of the DNI received from the official distributor with the original ID on two occasions, on October 15 and 17, 2022. Thus, if this operation had been carried out correctly, both duplicates would have been rejected.
Based on the above, in the case analyzed, the
diligence employed by the defendant to verify the identity of the person
who requested a duplicate SIM card is called into question.
In any case, it should be clear that following the protocols established for these procedures by DIGI is not sufficient to justify the lawfulness of the processing under the GDPR,
since these protocols do not satisfy the need for a legitimate basis.
Furthermore, the identity verification procedure followed by DIGI has not adequately guaranteed compliance with the GDPR.
Fifth argument: Regarding the inadmissibility of strict liability.
The defense rejects any attempt by the AEPD to impose strict liability, that is, to sanction the company simply for the outcome of the incident, without demonstrating fault or negligence. The respondent
argues that, pursuant to Constitutional Court Ruling No.
76/1990, the principle of culpability requires the existence of intent or negligence, and the mere
existence of an error does not justify the imposition of a sanction.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 23/36
Furthermore, the Ruling of the National Court of February 25, 2010, is cited,
according to which the overcoming of security measures by organized third parties is not sufficient grounds for sanctioning the affected company,
especially when adequate protective measures have been implemented.
Regarding DIGI's liability, it should be noted that, in general, DIGI
processes its customers' data under the provisions of Article 6.1 b) of the GDPR,
as processing is considered necessary for the execution of a contract to which
the data subject is a party or for the application, at the data subject's request, of pre-contractual measures.
In other cases, it bases the lawfulness of the processing on the bases
provided for in Article 6.1. a), c), e), and f) of the GDPR.
Furthermore, to complete the scam, it is necessary for a third party to "impersonate" the data subject in order to receive the duplicate SIM card. This
a priori entails processing that violates the principle of lawfulness, as a third party is
processing data, since it has access to it, without any legal basis, in addition to the
violation of other principles such as confidentiality.
Certainly, the principle of liability provided for in Article 28 of the LRJSP (Law of the Spanish Civil Code)
provides that: "Only natural and legal persons may be sanctioned for acts constituting an administrative infraction, as well as, when a law recognizes their capacity to act, groups of affected parties, unions and entities without legal personality, and independent or autonomous assets, who are found to be liable for such acts based on intent or negligence."
However, the method of attributing liability to legal persons does not correspond to the forms of intentional or reckless culpability that are attributable to human conduct. Thus, in the case of infractions committed by legal persons, although the element of culpability must be present, it is necessarily applied differently than it is to natural persons.
According to STC 246/1991, "(...) this different construction of the imputability of the authorship of the infringement to the legal entity arises from the very fictional nature of these subjects. They lack the volitional element in the strict sense, but not the capacity to violate the rules to which they are subject.
The capacity to violate and, therefore, direct blameworthiness derives from the legal asset protected by the rule being violated and the need for such protection to be truly effective and the risk that, consequently, must be assumed by the legal entity subject to compliance with said rule" (in this regard, STS of November 24, 2011, Rec 258/2009).
To the above, it should be added, following the judgment of January 23, 1998,
partially transcribed in the Supreme Court rulings of October 9, 2009, Rec 5285/2005, and of October 23, 2010, Rec 1067/2006, that "although the culpability of the conduct must also be subject to proof, it must be considered, in order to assume the corresponding burden, that the volitional and cognitive elements necessary to assess such conduct ordinarily form part of the proven typical conduct, and that their exclusion requires proof of the absence of such elements, or in their normative aspect, that the due diligence required by the person claiming their absence has been exercised; In short, the invocation of the absence of guilt is sufficient to exonerate oneself from typically unlawful behavior.
Likewise, it should be remembered that the San (National Supreme Court) of March 1, 2024 (RCA 0001757/2021)
provides that "In this regard, the Supreme Court of December 13, 2021 (Rec. 6109/2020)
establishes that "(...) the contracting company is required, as a necessary diligence
so that it cannot be accused of failing to comply with its obligations regarding
personal data protection—both with regard to the requirement
of the data subject's consent and with regard to the principle of truthfulness and accuracy—to implement control and verification measures aimed at ensuring
that the person seeking to contract is who they claim to be, that is, that they match the
holder of the DNI provided."
Thus, the data controller is required to verify the accuracy of the data
data subject's data by implementing appropriate measures when a contract is made. Precisely for this reason, it is necessary to ensure that the person contracting the service is who they claim to be, and appropriate preventive measures must be adopted to verify the identity of a person whose personal data will be processed. This is why the requirement for identification documents is based, as the Court has reiterated, among others, in judgments of October 3, 2013 (Recital 54/2012), November 21, 2014 (Recital 45/2014), etc.
Consequently, the lack of culpability is dismissed. Ultimate responsibility for the processing remains with the data controller, who is the one who determines the existence of the processing and its purpose. It should be recalled that, as a general rule, operators process their customers' data under the provisions of Article 6.1 b) of the GDPR, as processing is considered necessary for the execution of a contract to which the data subject is a party (...). In this regard, DIGI has a
network of sales representatives, points of sale, and distributors approved through a
distribution agreement to offer DIGI services. Among these services
offered from its points of sale is the production of SIM card duplicates
corresponding to a mobile phone line.
Sixth allegation: Regarding the lack of legal protection and security.
DIGI claims that not only has it been left with obvious legal protection and security, but it has also suffered from a lack of motivation and a lack of legal grounds.
The requirement to provide reasons for administrative acts, as indicated, among others, by the
Supreme Court of 19 November 2001 (Rec. 6690/2000), is constitutionally based on the
principle of legality established in Article 103 of the Spanish Constitution, as well as on the effectiveness of the
jurisdictional control of the Administration's actions recognized in Article 106 of the Spanish Constitution. At the legal level, Article 35.1 of Law 39/2015, on the Common Administrative Procedure of Public Administrations, is the provision that specifies the acts that must be reasoned. This requirement, according to reiterated jurisprudential doctrine, exemplified by the Supreme Court ruling of July 16, 2001 (Rec. 92/1994), is intended to enable the interested party to understand the when, how, and why of the Administration's decisions, with the necessary breadth to defend their rights and interests, while also allowing the courts to... C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 25/36
knowledge of the factual and regulatory details that will allow them to resolve the judicial challenge to the act, in the judgment of their power to review and control administrative activity; Thus, the lack of such motivation or its obvious inadequacy,
to the extent that it prevents the contestation of that act with a serious possibility of criticizing
the grounds and criteria on which it is based, constitutes a defect of voidability, as it leaves the interested party defenseless. Motivation of administrative acts, which, as stated in the Supreme Court of March 29, 2012 (Recital 2940/2010,
for all), does not require any exhaustive and detailed reasoning, and must express the reasons that allow for understanding the essential criteria underlying
the decision, "providing the interested parties with the necessary knowledge to assess the legal correctness or incorrectness of the act for the purposes of exercising the legal actions established by the legal system and adequately articulating their means of defense."
Well, in the present proceedings, a lack of motivation cannot be considered.
It is a different matter whether DIGI legitimately disagrees with this argument, but this does not imply a lack of sufficient motivation, and therefore neither defenselessness nor lack of legal certainty can be found for the violation identified in the proposed resolution.
For all these reasons, DIGI's request regarding the lack of liability cannot be granted.
Seventh allegation: Regarding the lack of proportionality of the proposed sanction.
DIGI requests that the following aggravating circumstances not be considered:
The intentionality or negligence of the violation (Article 83.2 b) of the GDPR.
It points out that, since this is an event caused by the commission of a criminal act by a third party not attributable to DIGI, it does not seem permissible to attribute this aggravating circumstance to it.
Any prior violation committed by the controller or processor.
It states that the general classification of this type of crime as SIM Swapping should not be confused with the existence of a common modus operandi or type of crime among all of them. It is not possible to demand absolute effectiveness of the measures designed to prevent fraud, since it is not possible to predict, even if extensive resources are dedicated to it, what the next possible activity will be that will require a new deployment of measures by DIGI.
The connection between its activity and the processing of personal data of clients or third parties (Article 83.2K of the GDPR in relation to Article 76.2 b of the LOPDGDD).
It points out that this aggravating factor must be put in context with the deployment of measures carried out by DIGI. In this sense, it indicates that the data processing does not arise from the entity's intention but rather from the commission of a crime in which DIGI is the injured party. For all these reasons, this aspect cannot be construed as an
aggravating circumstance.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 26/36
DIGI requests that the following mitigating circumstances be considered:
- At no time have special categories of data been processed (Art. 83.2 g
GDPR).
The respondent states that DIGI has not processed special category data, and that the
name, surname, and ID number are not part of the special categories (Art. 9 of the
GDPR).
- The degree of cooperation with the supervisory authority in order to remedy
the infringement and mitigate the potential adverse effects of the infringement.
Likewise, it states that it has responded in a timely manner to all requests for information
requested by this Agency (Article 83.2 f) GDPR).
- The non-existent benefit obtained.
Furthermore, it states that it has been harmed by the commission of fraud by a third party, which has forced it to remedy the situation and carry out investigations, with the associated consequences (Article 83.2k GDPR).
These allegations are addressed in Section VII (Fine Sanction: Determination of the Amount).
V
Breach of Obligation
Well, the defendant is charged with committing an infringement for violating
Article 6 of the GDPR, "Lawfulness of Processing," which sets forth in section 1 the
cases in which the processing of third-party data is considered lawful:
"1. Processing will only be lawful if at least one of the following
conditions is met:
a) the data subject has given their consent to the processing of their personal data
for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the request of the data subject, of pre-contractual measures;
c) processing is necessary for compliance with a legal obligation applicable to the data controller;
d) processing is necessary to protect the vital interests of the data subject or of another natural person;
e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data subject. the data controller;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 27/36
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. The provisions of point (f) of the first paragraph shall not apply to processing carried out by public authorities in the exercise of their duties.
It should be noted that data processing requires a legal basis.
Pursuant to Article 6.1 of the GDPR, in addition to consent, there are
other possible grounds that legitimize data processing without the need for the data subject's
authorization, in particular, when it is necessary for the performance of a contract to which the data subject is a party or for the implementation, at the data subject's request, of pre-contractual measures, or when it is necessary for the protection of legitimate interests pursued by the data controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject that require protection of such data. Processing is also considered lawful when it is necessary for compliance with a legal obligation to which the data controller is subject, to protect the vital interests of the data subject or another natural person, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
In the present case, the respondent is accused of violating Article 6.1 of the GDPR, as the unlawfulness of the processing carried out has been demonstrated, and none of the grounds for legitimation provided for in the aforementioned article have been established in relation to the processing of the complainant's data.
Processing is considered to be any operation carried out on personal data,
including the communication of such data to a third party. The GDPR, in Article 4.2,
defines processing as "any operation or set of operations
which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization,
structuring, storage, adaptation or modification, extraction, consultation,
use, disclosure by transmission, dissemination or any other form of
making available, alignment or combination, restriction, erasure or destruction."
The proceedings confirm that DIGI processed the complainant's personal data to issue two duplicate SIM cards for a mobile phone line owned by the complainant, which it subsequently provided to a third party without the complainant's consent and without any other legal basis for such processing of personal data.
This occurred because DIGI failed to verify the identity of the person who requested the duplicate SIM cards, failed to take the necessary precautions to prevent these incidents from occurring, and issued the duplicate cards without the complainant's intervention and knowledge. DIGI did not even comply with the protocols it has established to perform identity verification for requests of this type.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 28/36
On October 15 and 17, 2022, DIGI processed the issuance of two duplicate SIM cards belonging to the complainant. According to DIGI, in its response dated November 17, 2023:
"At the time of the events, a new SIM duplication procedure was in operation (...)".
And DIGI further states:
"(...)".
In this regard, it is worth clarifying that the SIM card is inserted inside the mobile device. It is a small, physical smart card that
contains a chip that stores the subscriber's service key
used to identify themselves to the network, that is, the client's mobile telephone line number (MSISDN)
as well as the subscriber's personal identification number (IMSI) (International Mobile Subscriber Identity). However, it can also provide other types of data, such as
information on the telephone list or calls and messages.
Furthermore, the issuance of a duplicate SIM card entails the processing of the holder's personal data, since an identifiable natural person is considered to be any person
whose identity can be determined, directly or indirectly, in particular,
through an identifier (Article 4.1 of the GDPR).
Therefore, the SIM card identifies a telephone number, and this number, in turn,
identifies its holder. In this regard, the CJEU judgment in Case C-101/2001 (Lindqvist) of 6 November 2003, paragraph 24, ECR 2003 p. I-12971: "The concept of 'personal data' used in Article 3(1) of Directive 95/46
in accordance with the definition in Article 2(a) of that directive, encompasses 'any information relating to an identified or identifiable natural person'. This concept undoubtedly includes a person's name together with their telephone number or other information relating to their working conditions or hobbies."
In short, both the data processed to issue a duplicate SIM card and the
SIM (Subscriber Identity Module) card that unequivocally and uniquely identifies the subscriber on the network are personal data, and their processing must be subject to data protection regulations.
Well, the result was that the respondent issued two SIM cards to a third party who was not the line owner and did not follow the verification procedure implemented by the respondent.
In light of the above, DIGI cannot prove that this procedure was followed.
In fact, DIGI states in its response to this Agency's request for information dated November 17, 2023, that it was a human error on the part of two back-office agents.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 29/36
Well, according to the identification procedure described by the respondent,
the two validating agents at DIGI's internal office did not verify the authenticity or compare the copy of the DNI received from the official distributor with the original ID document on two occasions, on October 15 and 17, 2022. Thus, if this operation had been carried out correctly, both duplicates would have been denied.
Furthermore, DIGI warns in the information provided to this AEPD that it sends an email and an SMS to the cardholder of the line to which the duplicate card issued corresponds.
However, these communications are sent after the duplicates have already been validated, leaving the cardholder no opportunity to react to prevent this.
Based on the above, in the case analyzed, the
diligence employed by the respondent to verify the identity of the person
who requested a duplicate SIM card is called into question.
Ultimately, the issuance of a duplicate SIM card necessarily entails the
processing of personal data. Such processing must comply with a legal basis
that legitimizes it, as required by the aforementioned Article 6.1 of the GDPR, as is any
communication of personal data to a third party.
In this case, the issuance of duplicate SIM cards at the request of a third party without the intervention or consent of the data subject constitutes a lack of a valid legal basis for such data processing.
It is deemed appropriate to reiterate that following the protocols established for these procedures by DIGI is not sufficient to justify the lawfulness of the processing under the GDPR, since these protocols do not satisfy the need for a legitimate basis, and the identity verification procedure followed by DIGI has not adequately guaranteed compliance with the GDPR.
Therefore, the issuance of duplicate SIM cards under these conditions and their delivery to a person other than the telephone line owner constitutes processing of personal data without a legal basis and, consequently, a violation of Article 6.1 of the GDPR, given that it was carried out without complying with any of the legitimate bases for such processing. Liability does not lie in the failure to comply with an internal protocol, but in the absence of a valid legal basis in accordance with the provisions of the GDPR.
Based on the available evidence, it is considered that the conduct of the respondent party could violate Article 6.1 of the GDPR and could constitute the infringement defined in Article 83.5.a) of the aforementioned Regulation 2016/679.
In this regard, Recital 40 of the GDPR states:
“(40) For processing to be lawful, personal data must be processed with the
consent of the data subject or on another legitimate ground established by law, whether by this Regulation or by other Union or Member State law to which this Regulation refers, including the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 30/36
necessity for compliance with a legal obligation applicable to the controller or the
necessity for the performance of a contract to which the data subject is party or in order to
take steps at the request of the data subject prior to entering into a
contract.”
Based on the foregoing, DIGI is deemed to have violated Article 6.1 of the GDPR.
VI
Classification and classification of the violation
The violation is defined in Article 83.5 of the GDPR, which states:
"5. Violations of the following provisions shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of a company, by an amount equivalent to a maximum of 4% of the total annual global turnover of the preceding financial year, whichever is higher:
a) The basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7, and 9."
For the purposes of the statute of limitations for infringements, Article 72.1 of the LOPDGD classifies as a very serious infringement, in which case the statute of limitations is three years, “b)
The processing of personal data without any of the conditions for the lawfulness of the processing established in Article 6 of Regulation (EU) 2016/679 being met.”
VII
Sanction
In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article for infringements of this Regulation indicated in paragraphs 4, 9, and 6 are, in each individual case, effective, proportionate, and dissuasive.”
“Administrative fines shall be imposed, depending on the circumstances of each individual case, in addition to or as a substitute for the measures provided for in Article 58, paragraph 2, letters a) to h) and j). When deciding whether to impose an administrative fine and its amount in each individual case, due account shall be taken of:
a) the nature, severity, and duration of the infringement, taking into account the
nature, scope, or purpose of the processing operation in question,
as well as the number of data subjects affected and the level of damage they have suffered;
b) the intentionality or negligence involved in the infringement;
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 31/36
c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects;
d) the degree of responsibility of the controller or processor, taking into account the technical measures or organizational measures that have been implemented pursuant to Articles 25 and 32;
e) any previous breaches committed by the controller or processor;
f) the degree of cooperation with the supervisory authority in order to remedy the breach and mitigate the potential adverse effects of the breach;
g) the categories of personal data affected by the breach;
h) how the supervisory authority became aware of the breach,
in particular whether the controller or processor notified the breach and, if so, to what extent;
i) where measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;
j) adherence to codes of conduct pursuant to Article 40 or certification mechanisms approved pursuant to Article 42; and
k) any other aggravating or mitigating factors applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.”
Regarding section k) of Article 83.2 of the GDPR, Article 76 of the LOPDGDD, "Sanctions and Corrective Measures," provides:
"2. In accordance with the provisions of Article 83.2.k) of Regulation (EU) 2016/679,
the following may also be taken into account:
a) The continuous nature of the infringement.
b) The connection between the offender's activity and the processing of personal data.
c) The benefits obtained as a result of the infringement.
d) The possibility that the affected party's conduct could have led to the infringement.
e) The existence of a merger by absorption process subsequent to the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
g) Having, when not mandatory, a data protection officer.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 32/36
data.
h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in those
cases where there are disputes between them and any interested party."
In accordance with the transcribed provisions, for the purposes of determining the amount of the fine to be imposed on the respondent, as the party responsible for an infringement classified as Article 83.5.a) of the GDPR, the following factors are considered concurrent:
DIGI requests that the following mitigating circumstances be considered:
(I) "At no time have special categories of data been processed" (Article 83.2 g).
(II) "The degree of cooperation between DIGI and the AEPD," Article 83.2 f) of the GDPR.
(III) "The non-existent benefit obtained by DIGI," Article 83.2 k) of the GDPR.
None of the mitigating circumstances invoked are admissible.
Article 83.2 g) of the GDPR states, "At no time have special categories of data been processed."
The data processed by DIGI are sensitive data, used to identify its customers in the procedures carried out to obtain a duplicate SIM card.
The data are the name, surname, and ID number. These are personal data associated with a telephone line owned by a user, which is obtained for the purpose of impersonating the user.
This is personal data whose unauthorized access is particularly serious.
This is without prejudice to the fact that, for the purpose of issuing the duplicate of the aforementioned card, personal data such as the name, surname, and ID number of the holder have been processed.
It should be remembered that the numerical ID number identifies a natural person beyond all doubt. This quality makes it particularly sensitive data because, if its processing is not accompanied by the necessary technical and organizational measures to ensure that the person identified with it is truly its owner, a third party can easily impersonate a natural person, or, in other words, commit identity fraud, with the associated risks to the privacy, honor, and assets of the person impersonated. Therefore, this circumstance is taken into account when determining the sanction to be imposed.
Article 83.2.f) of the GDPR refers to the "degree of cooperation with the supervisory authority in order to remedy the infringement and mitigate the potential adverse effects of the infringement."
The respondent's response to the information request from the Inspection Subdirectorate did not fulfill these purposes, and therefore does not qualify as such a mitigating circumstance.
Regarding the application of Article 76.2.c) of the LOPDGDD, in conjunction with Article 83.2.k), the lack of benefits obtained, it should be noted that such a circumstance can only operate as an aggravating factor and in no case as an mitigating circumstance.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 33/36
Article 83.2.k) of the GDPR refers to “any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.” And Article
76.2c) of the LOPDGDD states that “2. In accordance with the provisions of Article 83.2.k) of
Regulation (EU) 2016/679, the following may also be taken into account: [...] c) Benefits obtained as a result of committing the infringement.” Both provisions
mention as a factor that may be taken into account in scaling the sanction the “benefits” obtained, but not the “absence” of benefits, which is what DIGI claims.
Furthermore, pursuant to Article 83.1 of the GDPR, the imposition of fines is governed by the following principles: they must be individualized for each particular case, effective, proportionate, and dissuasive. Accepting that the absence of profits operates as a mitigating factor is contrary to the spirit of Article 83.1 of the GDPR and the principles that govern the determination of the fine. If, following the commission of a GDPR violation, the lack of profits is considered a mitigating factor, the deterrent purpose served by the fine is partially negated. Accepting DIGI's argument in a case such as the one at hand would mean introducing an artificial reduction in the penalty that truly should be imposed; this reduction results from considering the circumstances of Article 83.2 of the GDPR that must be assessed. The Administrative Litigation Division of the National Court has noted that the fact that, in a specific case, not all the elements that constitute a circumstance modifying liability, which by its nature is aggravating, are present, cannot lead to the conclusion that such a circumstance is applicable as a mitigating circumstance. The ruling made by the National Court in its Supreme Court of May 5, 2021 (Recital 1437/2020)—even though that ruling deals with the circumstance in section e) of Article 83.2 of the GDPR, the commission of prior violations—can be extrapolated to the question raised: the respondent's claim that the "absence" of benefits be accepted as a mitigating circumstance, given that both the GDPR and the LOPDGDD refer only to "the benefits obtained."
For the purposes of graduating the amount of the proposed fine imposed on DIGI
for violating Article 6.1 of the GDPR, we consider that the following circumstances exist, which act as aggravating factors:
- Intentionality or negligence in the violation (Article 83.2. b) of the GDPR). In this
case, we are dealing with gross negligence, as the defendant has issued SIM cards up to
on two occasions to a third party who was not the owner of the line, under the circumstances described in the proven facts.
In this regard, the Supreme Court ruling of October 17, 2007 (rec. 63/2006) is very illustrative, stating that "...the Supreme Court has considered that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not behave with the required diligence. And in assessing the degree of diligence, the professionalism of the individual must be especially considered, and there is no doubt that, in the case now under review, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 34/36
- The circumstance of Article 83.2 e) GDPR: “Any previous infringement committed
by the controller or processor.”
-
Recital 148 of the GDPR states that “In order to strengthen the application of the
rules of this Regulation […]” and indicates in this regard that “However, particular attention should be paid
to […] or any relevant previous infringements […].”
Thus, pursuant to Article 83.2 e) GDPR, in determining the
amount of the administrative fine, all previous infringements by the controller or processor may not be overlooked in order to assess the unlawfulness of the conduct under analysis or the culpability of the offending party.
Furthermore, a correct interpretation of Article 83.2.e) GDPR cannot ignore the purpose of the regulation: to determine the amount of the administrative fine in the individual case, always ensuring that the penalty is proportional, effective, and dissuasive.
There are numerous sanctioning procedures processed by the AEPD in which the respondent has been sanctioned for violating Article 6.1 GDPR:
i.EXP 202104009 Resolution issued on March 15, 2023, imposing a
fine of €70,000. The facts involved a fraudulent duplicate SIM card
without legal basis.
ii.EXP202201226. Resolution issued on March 14, 2023, imposing
a fine of €70,000. The facts involved a fraudulent duplicate SIM card without legal basis.
iii.EXP202204881 Resolution issued on June 2, 2023, imposing a fine of €70,000. The facts involved a fraudulent duplicate SIM card without legal basis.
- The evident link between the respondent's business activity and the processing of personal data of clients or third parties (Article 83.2.k of the GDPR in conjunction with Article 76.2.b of the LOPDGDD).
The respondent's business activity necessarily processes personal data,
as it is a very important telecommunications company in Spain. This characteristic of its business activity has a significant impact on the diligence it must demonstrate in complying with the principles governing the processing of personal data and in the quality and effectiveness of the technical and organizational standards it must implement to ensure respect for fundamental rights. The National Court's ruling of 10/17/2007 (rec. 63/2006), in which,
regarding entities whose activity involves the continuous processing of customer data, states that "...the Supreme Court has considered that negligence exists whenever a legal duty of care is disregarded, that is, when the offender fails to behave with the required diligence. And in assessing the degree of diligence, the professionalism or lack thereof of the subject must be especially considered, and there is no doubt that, in the case now under consideration, when the appellant's activity involves constant and extensive handling of personal data, rigor and exquisite care must be emphasized to comply with the legal provisions in this regard."
The penalty to be imposed on the defendant must be graded and set at €200,000 for the violation of Article 83.5 a) of the GDPR, classified as very serious for the purposes of the statute of limitations in Article 72.1 b) of the LOPDGDD.
Therefore, in accordance with applicable legislation and having assessed the criteria for grading the penalties whose existence has been proven,
the Presidency of the Spanish Data Protection Agency RESOLVES:
FIRST: TO IMPOSE on DIGI SPAIN TELECOM, S.L.U., with NIF B84919760, for a
violation of Article 6.1 of the GDPR, classified in Article 83.5.a) of the GDPR, a
fine of two hundred thousand euros (€200,000).
SECOND: NOTIFY this resolution to DIGI SPAIN TELECOM, S.L.U.
THIRD: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration expires (one month from the day following notification of this resolution) without the interested party having exercised this right.
The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b)
of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period
established in Article 68 of the General Collection Regulations, approved by Royal
Decree 939/2005, of July 29, in relation to Article 10. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the sanctioned party's NIF (Tax Identification Number) and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be carried out during the enforcement period.
Once the notification is received and enforced, if the enforcement date is between the 1st and 15th of each month, inclusive, the deadline for making the voluntary payment will be the 20th of the following month or the next business day after, and if it is between the 16th and last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day after.
In accordance with the provisions of Article 50 of the LOPDGDD (Spanish Organic Law on the Protection of Personal Data), this Resolution will be made public once it has been notified to the interested parties.
Against this resolution, which terminates the administrative process pursuant to Art. 48.6 of the
LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, interested parties may optionally file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an administrative appeal before the Administrative Litigation Division of the
National Court, in accordance with the provisions of Article 25 and Section 5 of the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Administrative Litigation Jurisdiction, within two months from the day following notification of this decision, as provided for in Article 46.1 of the
referred Law.
Finally, it is noted that, in accordance with the provisions of Article 90.3 a) of the LPACAP, a final administrative decision may be provisionally suspended if the
interested party expresses their intention to file an administrative appeal.
If this is the case, the interested party must formally notify this fact in writing to the Spanish Data Protection Agency, submitting it through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica-
web/], or through one of the other registries provided for in Article 16.4 of the
cited Law 39/2015, of October 1. They must also submit to the Agency the
documentation proving the effective filing of the administrative appeal. If the Agency does not become aware of the filing of the administrative appeal within two months from the day following notification of this resolution, it will terminate the precautionary suspension.
LORENZO COTINO HUESO
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es




