AEPD (Spain) - EXP202315096
| AEPD - EXP202315096 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(2) GDPR Article 6(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 14.02.2024 |
| Decided: | |
| Published: | 15.01.2026 |
| Fine: | 200,000 EUR |
| Parties: | Telefónica Móviles España, S.A |
| National Case Number/Name: | EXP202315096 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | RP |
The DPA fined a telephone operator €200,000 for issuing a duplicate SIM without properly identifying its customer which allowed for a SIM-swap fraud and resulted in harm to the customer.
English Summary
Facts
A data subject used a mobile phone line provided by Telefónica Móviles España, S.A. (the controller). In January 2023, their phone stopped working. The data subject requested a duplicate SIM card and discovered that a third party had already received a duplicate SIM for their line. The third party used the SIM card to access the data subject’s bank accounts and committed financial fraud.
The data subject complained to the controller and later to the Spanish Data Protection Agency (AEPD). They argued that the controller issued a duplicate SIM card without their consent and without properly verifying the identity of the requester.
The controller confirmed that it issued duplicate SIM cards on 17 January 2023 and 19 January 2023. The controller stated that it had identity verification procedures and that a criminal third party had deceived its staff. The controller also stated that it could not provide additional records showing how it verified the identity of the person who requested the SIM duplicate.
The AEPD started an administrative procedure against the controller for a possible violation of Article 6 GDPR. The controller argued that the processing was lawful because it was necessary for the performance of the contract. It also argued that the fraud was caused by a third party, that it had acted in good faith, and that the proposed fine was disproportionate.
Holding
The AEPD held that the controller unlawfully processed the data subject’s personal data. The AEPD found a violation of Article 6(1) because the controller issued a duplicate SIM card without a valid legal basis. The controller could not prove that the data subject requested the SIM card or that they consented to the processing.
The AEPD referred to the accountability principle in Article 5(2). The controller had to implement appropriate technical and organisational measures and had to demonstrate that these measures were effective. The controller failed to provide evidence that it verified the identity of the requester.
The AEPD rejected the controller’s argument that third-party fraud removed its responsibility. The authority stated that controllers must prevent foreseeable risks such as SIM-swap fraud. The controller had a high duty of care because it processed large amounts of personal data in the telecommunications sector. The AEPD considered the infringement negligent because the controller could have prevented the incident with proper identity verification measures.
The AEPD classified the infringement under Article 83(5). It assessed the fine based on the seriousness of the infringement, the controller’s turnover, and the need for an effective, proportionate, and dissuasive sanction. The AEPD imposed a fine of €200,000 on Telefónica.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/46 • File No.: EXP202315096 RESOLUTION OF SANCTIONING PROCEEDINGS From the proceedings initiated by the Spanish Data Protection Agency and based on the following: BACKGROUND FIRST: The Consumers' Union of Asturias, on behalf of and representing A.A.A. (hereinafter, the complainant), filed a complaint with the Spanish Data Protection Agency on October 4, 2023. The complaint is directed against TELEFÓNICA MÓVILES ESPAÑA, S.A., with Tax Identification Number A78923125 (hereinafter, the respondent; TELEFÓNICA; TME; or O2). The grounds for the claim are as follows: The claimant states that in January 2023, for no apparent reason, their mobile phone line ***TELÉFONO.1 became inoperative. Therefore, they requested a duplicate SIM card and collected it from a TME point of sale. Subsequently, they realized they had been the victim of identity theft to carry out fraudulent transactions on the joint account they hold with their wife, totaling ***AMOUNT.1 euros, using the duplicate SIM card. The claimant contacted O2, who informed them that a duplicate SIM card had previously been requested. The claimant stated that this was not them and requested the recordings and documents signed by the third party who requested the SIM card. The complainant states that they do not understand how O2 provided a duplicate SIM card without their consent or their ID, without following the appropriate security procedures to verify the identity of the requestor. The complainant states that, with this fraudulently issued SIM card, they have been defrauded of ***AMOUNT.1 euros, through (…) unauthorized charges to their bank account. They submit, among other documents, the following relevant documentation: - Authorization to the Consumers' Union of Asturias and the complainant's ID. - Proof of two bank account charges for ***AMOUNT.2 and ***AMOUNT.3 euros. - “SIM card replacement agreement” signed by the complainant with TME on January 19, 2023, corresponding to line ***PHONE.1. - Complaint to O2 dated June 21, 2023, stating that the line was lost and that a fraudulent request was made. - O2's response to the complaint indicating: “that the duplicate was requested in a store on January 17, 2023, at 2:18 p.m., and therefore, in order to issue the duplicate, the cardholder's ID had to be presented in the store.” - Emails from the complainant to O2, requesting information about the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 2/46 fraudulent duplicate. - Telefónica's response, dated June 23, 2023, indicating that their systems show requests for duplicate SIM cards associated with your line made on January 17 and 19, 2023, and that they cannot be held responsible for potential bank fraud, and that they proceeded to refund the amount paid for the issuance of a new SIM card. TME adds that "the remaining information regarding these requests is stored and will be made available to the competent authorities during the investigation, through the channels established by Movistar for this purpose." - Email from O2, indicating that the fraudulent duplicate SIM card was cancelled. - Claim filed with the financial institution dated June 20, 2023. - Response from the financial institution to the claimant dated April 21, 2023, regarding the issue experienced with their online banking, indicating that they would not grant the request for a refund of the claimed amount. - Proof of the bank fraud. - Report filed with the National Police in [LOCATION] dated January 20, 2023, by the claimant's wife regarding the two fraudulent charges made to their bank account. This complaint makes the following statements regarding the mobile phone line in question: The complainant wishes to state that on January 17, 2023, her phone service was interrupted. When contacted, O2 told her it could be a problem with the SIM card. After purchasing another SIM card, she still had no service and, upon contacting the company again, was told that the line was blocked due to possible fraud. To date, she has sent an email requesting information about this block and has not yet received a response. The blocked phone number is ***PHONE.1, and it is currently functioning normally. SECOND: In accordance with Article 65.4 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the complaint was forwarded to the respondent so that they could analyze it and inform this Agency, within one month, of the actions taken to comply with the requirements of data protection regulations. The forwarding, which was carried out in accordance with the rules established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), was received on October 31, 2023, as evidenced by the acknowledgment of receipt included in the file. On December 21, 2023, this Agency received a written response stating: “(…) 2. Regarding the channel through which the SIM card duplicate was processed and the method of identification of the person who requested it. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 3/46 Telefónica reports that a request for an ICC change of the SIM card of the Complainant was made on January 17, 2023, through one of our authorized Points of Sale. On January 19, 2023, another ICC change was requested through another authorized Point of Sale. 3. Regarding the documentation and data provided by the person who requested the SIM card to prove their identity and the registration in your systems of the identity verification checks: A Telefónica, having reviewed its systems, has no record of any additional information in this regard. (…) THIRD: On December 28, 2023, in accordance with Article 65 of the LOPDGDD (Spanish Data Protection Act), the complaint filed by the complainant was admitted for processing. FOURTH: The Sub-Directorate General for Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in question, by virtue of the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VII, Chapter I, Section Two, of the LOPDGDD, having become aware of the following: First, regarding the SIM card change request dated January 17 Regarding the SIM card replacement request dated January 19, 2023, Telefónica has no further information beyond what was already provided in the letter sent to this Agency on December 18, 2024. Secondly, regarding the SIM card replacement request dated January 19, 2023, we confirm that this request was made through one of our authorized physical stores. Following the procedure already reported to this Agency for verifying customer identity, this verification was carried out through “***SYSTEM.1” (…). Attached as Document No. 1 are the images obtained from their system showing the aforementioned (…). FIFTH: According to the report obtained from the AXESOR tool, the entity TELEFÓNICA MÓVILES ESPAÑA, S.A., a large company established in 1988, with a turnover of ***AMOUNT.4 euros in the year 2024. SIXTH: On December 23, 2024, the Director of the Spanish Data Protection Agency (AEPD) agreed to initiate sanction proceedings against the respondent, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the GDPR, as defined in Article 83.5 of the GDPR. The opening agreement determined that the sanction that could be imposed for C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 4/46 the alleged infringement, without prejudice to the outcome of the investigation, would be €300,000 (three hundred thousand euros). SEVENTH: Notified The aforementioned agreement to initiate proceedings, in accordance with the rules established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), prompted the respondent to request an extension of the deadline. This extension was granted, and on January 28, 2025, the respondent submitted a statement of allegations, stating the following: PRELIMINARY ISSUE. - CRIMINAL PREJUDICIALITY First, Telefónica requests that the Agency suspend the proceedings and require the Complainant to provide information on the status of the complaint filed, as well as the content of any criminal proceedings that may be underway. In the meantime, the Agency requests the suspension of these proceedings due to the close relationship between the criminal and administrative proceedings. I. ON THE FACTS THAT MOTIVATE THE INITIATION OF THIS AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS FIRST. - NO COMMISSION OF AN INFRACTION. DISAGREEMENT WITH THE AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS Telefónica expresses its complete disagreement with the initiation of these sanctioning proceedings and with the established facts set forth in the grounds for the Agreement, indicating that, from the responses made by the respondent to the information requests made by the Agency, it cannot be inferred in any way that they imply admission, presumption, or verification by the Agency that the sales agent did not follow the procedures regarding customer identification. Telefónica states that there is no sufficient evidence to overcome Telefónica's presumption of innocence demonstrating a lack of verification of the identity of the person requesting the duplicate eSIM card, nor to demonstrate a lack of application of the required safeguards. In this regard, the defendant points to the technical and organizational measures implemented by Telefónica that are appropriate for the management of the matter that gives rise to this Agreement, namely, duplicate SIM or eSIM cards, and specifically their processing under the "O2" brand, given that this is the brand under which the mobile services subject to these proceedings are provided. In this regard, Telefónica indicates that, according to standard procedures, the identity checks had to be carried out, given that it has a well-established and adequate procedure for verifying the identity of its customers, which provides sufficient guarantees to identify the applicant for the duplicate eSIM card, and the Agency has not been able to provide sufficient evidence to prove that this was not the case. The absence of a copy of the contract does not imply that the identification was not performed correctly. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 5/46 II. THE CIRCUMSTANCES THAT MADE IT POSSIBLE FOR THIRD PARTIES TO BREAK THROUGH THE SECURITY POLICIES IMPLEMENTED BY TELEFÓNICA. FIRST. - REGARDING THE ALLEGED INFRINGEMENT COMMITTED BY TELEFÓNICA: LACK OF LEGALITY, UNLAWFULNESS, AND CULPABILITY. It considers that the principle of legality is being violated since the conduct carried out by Telefónica cannot be subsumed under any of the provisions whose infringement is alleged. It notes that the Agency considers Article 6.1 of the GDPR (conditions under which processing will be considered lawful) to have been violated and classifies the infringement according to Article 83.5 GDPR. However, the Agency does not specify which of the legal bases listed in Article 6.1 would be necessary to carry out the processing of the claimant's data that gave rise to this Agreement, so that it could be considered legitimate. The respondent argues that the legal basis legitimizing the processing of the claimant's personal data is none other than the performance of the contract, that is, the legal basis contemplated in section b) of the aforementioned Article 6.1: “the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.” The respondent indicates that, in this specific case, the processing of personal data is carried out for the purpose of managing a duplicate SIM card for the proper provision of the service, or in other words, to be able to perform the contract that the claimant has signed with Telefónica. Therefore, the processing is lawful in any case. TME maintains that it acted at all times in good faith and with a well-founded belief excluding any culpability, and points out that the unlawfulness of the conduct is a element constituting any administrative offense, requiring, in its formal aspect, that there be a conflict between the behavior and the violated rule. Therefore, if the behavior is sanctioned by the legal system, it can never be considered unlawful conduct, nor, consequently, punishable. Thus, “TME” rejects the unlawfulness of the conduct. SECOND. – ABSENCE OF CULPABILITY. MISTAKE OF FACT. “TME” argues that the requirement of culpability is not met in its actions, and that the guiding principles of criminal law are applicable to administrative sanctioning law, noting that one of the main components of an administrative infraction is the element of culpability, which presupposes that the action or omission must in all cases be attributable to its author due to malice, recklessness, negligence, or inexcusable ignorance—requirements that are not met in this case. Therefore, even if the Agency considers that there has been unlawful data processing by this party, deeming Telefónica's action to be typical and unlawful, it cannot be asserted that Telefónica's conduct can be considered culpable. Furthermore, it states that the SIM card replacement process was carried out in its entirety. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 6/46 as a result of acts of deception, manipulation, and illicit use of data by a third party, who allegedly deceived the sales agent into believing that they were the data subject or that they had the data subject's consent to make the request, having correctly identified themselves with the customer data in their systems. It notes that, in this case, where, according to standard procedure, the customer identified themselves with the correct data for the SIM card replacement request, it is established that this was an unavoidable error, where the unlawfulness of the conduct was unknown, and therefore the proceedings should be closed, as Telefónica's culpability cannot be determined. THIRD. – VIOLATION OF THE PRINCIPLE OF PROPORTIONALITY IN SANCTIONS TME states that the imposed sanction violates the principle of proportionality that should govern the sanctioning power of the Administration. It cites a series of rulings, including the Supreme Court ruling of June 2, 2003, and the ruling of October 30, 2020, from the contentious-administrative appeal number 948/2018 of the National Court. It points out the aggravating circumstances considered that are not applicable to the specific case: - The circumstance outlined in Article 83.2.b) of the GDPR, relating to the intent or negligence of the infringement: TME notes that the Agency states in this regard that "in this case we are dealing with a serious act of negligence, since the defendant does not verify the identification of the SIM card applicant at the point of sale." It points out that Telefónica's attitude reveals an unequivocal willingness to proceed in accordance with the law, without any intention whatsoever to infringe the regulation, and with a clear intention to comply. Telefónica has the necessary and appropriate technical measures in place for managing SIM card duplication. SIM card. Therefore, in this case, one cannot speak of intent or negligence in the infraction. Furthermore, it points out that in any case, TME understands that the type of infraction charged already assumes, by itself, the culpable element of the negligence being judged, so given that there is no additional or greater intensity in the sanctioned party's conduct, it should not have been taken into account as an aggravating factor for the purposes of imposing the sanction. In this regard, it cites the criteria followed by the First Section of the Administrative Chamber of the National Court, which would support this position, specifically, in its recent Judgment of July 1, 2024 (Appeal No. 900/2022): “The claim alleges that two aggravating circumstances have been taken into account, consisting of the plaintiff's negligence in modifying the contract without being certain that the person who called requesting the change of Power C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 7/46 acting on behalf of the contract holder (Art. 83.2.b GDPR (EDL 2016/48900)). And the connection of the infringer's activity with the processing of personal data (Art. 76.2.b of Organic Law 3/2018 (EDL 2018/128249)). Regarding the proportionality of the sanction, this is understood as the appropriateness, according to criteria of justice and equity, between the facts constituting the infringement and the determination of the applicable sanction, taking into account the degree of fault involved, that is, the level of intent, carelessness, or negligence revealed by the conduct. And, of course, a justification for the assessment of the degree of fault involved is required. This brings us to the first of the aggravating circumstances discussed. It is evident that these sanctions can only be imposed if there is fault or negligence. Therefore, without the element of fault, no infraction of any kind can be considered. This leads us to consider that said element of fault is inherent in the nature of the infraction. For this reason, this Court understands that unless the existence of excessive intent or an additional degree of fault in the conduct of the sanctioned party is demonstrated, proven, and justified, the fault or negligence must be considered an integral part of the infraction without being elevated to the category of an aggravating circumstance. In this case, there is no evidence of intent or negligence greater than that of the infraction that could be taken into consideration to increase the severity of the sanctioned act in either of the two infractions. Therefore, this aggravating circumstance is excluded, resulting in a reduction of the monetary penalty. All of the above provides more than enough grounds for the Agency to, as a subsidiary measure, reduce the sanction or sanctions it ultimately imposes. - The circumstance outlined in Article 83.2.e) of the GDPR, relating to any infringement committed by the controller or the processor: The Agency also takes into account, for the purposes of calculating the amount of the sanctions, the circumstance of Article 83.2.e) of the GDPR, expressly mentioning the sanctioning procedures: - EXP202206971 Resolution issued on March 9, 2023, in which a sanction of €70,000 was imposed. The facts concerned a fraudulent duplicate SIM card without authorization. - EXP 202207989 Resolution issued on November 13, 2023, imposing a fine of €70,000. The case involved a fraudulent duplicate SIM card without authorization. - EXP202211479 Resolution issued on June 13, 2023, imposing a fine of €70,000. The case involved a fraudulent duplicate SIM card without authorization. - EXP202209359 Resolution issued on June 16, 2023, imposing a fine of €70,000. The case involved a fraudulent duplicate SIM card without authorization. ... In this regard, it should be noted that: - Sanctioning resolution EXP202206971 became final on May 13, 2023, after all administrative appeals were exhausted. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/46 Sanctioning resolution EXP202207989 did not even become final until December 20, 2023, after all administrative appeals were exhausted. - Sanctioning resolution EXP202211479 would not have become final until July 19, 2023, after all administrative appeals were exhausted. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 8/46 -The sanctioning resolution EXP202209359 would not have become final through administrative channels until August 19, 2023, once the possibility of filing appeals through administrative channels had been exhausted. Given this fact, the typical actions being judged in this sanctioning proceeding stem from an event that occurred on January 19, 2023, that is, prior to the referenced sanctioning resolutions. It is clear, therefore, that when the SIM card was duplicated, that is, on January 19, 2023, no sanctioning resolution had been issued, much less one that was "final" through administrative channels, for acts of the same or similar nature. Therefore, the requirement of a prior sanction for the acts in question, which is necessary for the application of the aggravating circumstance of recidivism, was not met. This is established by the jurisprudence of the Supreme Court, which has repeatedly affirmed (among others, we cite the judgments of October 24, 2000, March 11, 2003, March 23, 2005, and September 30, 2009) that the aggravating circumstance of administrative recidivism must refer to acts that had already been sanctioned in another proceeding resolved prior to the commission of the new offense. Furthermore, in any case, and as the Agency is well aware, all the sanctioning proceedings have been appealed by this party before the National Court, since it considers the resolutions leading to the imposition of the sanction to be null and void, as the principle of legality is not met in any of them. In this regard, and insofar as the Courts of Justice are still ruling on the matter and there is no final decision, this party believes that this aggravating circumstance should not be considered. Otherwise, if the appeals filed are upheld, this party would suffer enormous harm. Consequently, this aggravating circumstance should also not be taken into account, and the amount of the sanction or sanctions that are ultimately imposed should be reduced. - When the Agency considers the link between the defendant's business activity and the processing of personal data of clients or third parties as an aggravating circumstance: The Agency takes into account the following circumstance to aggravate Telefónica's conduct: “The evident link between the defendant's business activity and the processing of personal data of clients or third parties (Article 83.2.k of the GDPR in relation to Article 76.2.b of the LOPDGDD).” “TME” considers that there has been no unlawful processing of the claimant's data, since its processing is legitimized by Article 6.1 of the GDPR, being necessary for the performance of a contract to which the data subject is a party. Therefore, it cannot be considered an aggravating circumstance. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 9/46 It also indicates that the Agency considers, de facto, that since “TME” manages a high volume of data processing, this aggravating circumstance should be applied. “TME” points out that in this case, the following mitigating circumstances of Article 83.2 of the GDPR are present, which have been overlooked by the Agency in the Initial Agreement: b) intent or negligence in the infringement: “TME” states that in this case, the requirements of intent in the alleged commission of the infringement or negligent conduct are not met, since it was a third party who processed the Complainant's personal data without their consent. c) The respondent resolved the issue that was the subject of the complaint effectively: as indicated in the responses to the information requests, the line in question was subsequently restored to the customer as soon as possible, and once Telefónica was informed of the situation, the SIM card cost was refunded. c) any measures taken by the data controller or processor to mitigate the damages suffered by the data subjects: Telefónica took the appropriate actions, strengthening the procedures established for this purpose. Furthermore, the procedures have proven to be completely robust, based on the figures presented. (j) Adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42: Telefónica has signed the Self-Regulation Code of Conduct on data processing in advertising, which is an out-of-court dispute resolution system for resolving disputes arising between citizens and entities adhering to the code regarding data processing carried out in the context of advertising. FOURTH. - EQUITY AND DOUBLE DOUBLE “TME” points out that the Agency’s actions regarding a case file concerning events substantially identical to those that are the subject of the present claim have been contradictory, as the Agency itself informed us in file reference No. EXP202104446 dated January 26, 2022, in which it proceeded to close the case on the grounds that there was already a sanctioning procedure underway for the same events, the text of which was as follows: “On this matter, it is worth highlighting that similar events to those that are the subject of this claim have been investigated by this Agency and sanctioned in sanctioning procedure PS/00021/2021, processed against the party being claimed, by resolution dated November 8, 2021, therefore, the initiation of a new sanctioning procedure is not warranted.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 10/46 It indicates that in all sanctioning proceedings initiated against Telefónica for similar acts, such as in sanctioning proceedings EXP202209359, EXP202207989, EXP202211479, or EXP202206971, the Agency has always considered, in every case, the mitigating circumstance of having effectively resolved the incident that was the subject of the complaint, something that is present in this case and is being overlooked (e.g., Sanctioning Resolution of EXP202206971: “As mitigating circumstances: The respondent proceeded to block the line as soon as it became aware of the facts (Art. 83.2 c)”) It affirms that the discrepancy in the administrative action between one file and Another would constitute a clear violation of the doctrine of estoppel. Furthermore, it points out that Telefónica has already been sanctioned for the same events that are the subject of this procedure, and that the Agency imposed the sanction through procedure with reference PS/00021/2021. “TME” considers that initiating a new sanctioning procedure, successively, without a ruling from the Courts of Justice, and on the same events, violates the principle of double jeopardy. It indicates that, according to the established doctrine of the Constitutional Court, the Spanish Constitution prohibits the imposition of more than one punishment for the same offense. This prohibition constitutes the substantive aspect of the guarantee against double jeopardy, and the Constitutional Court has held that, although not expressly stated in the constitutional text, it must be considered implicit in Article 25.1 of the Spanish Constitution due to its close connection with the principle of punitive legality, as proclaimed early on by Constitutional Court Ruling 2/1981, of January 30, and which all Administrative Courts have adopted: - Constitutional Court Ruling 2/1981, of January 30: “although the principle of double jeopardy is not expressly included in Articles 14 to 30 of the Constitution, which recognize the rights and freedoms subject to protection, it is nonetheless that it should not be ignored that, as the members of Parliament in the Committee on Constitutional Affairs and Public Liberties of the Congress understood when they omitted it in the drafting of Article 9.1 of Preliminary Draft 21 of the Constitution, it is intimately linked to the principles of legality and specificity of offenses, mainly contained in Article 25 of the Constitution.” - Constitutional Court Judgments 2/2003, of January 16, and 48/2007, of March 12: “The principle of double jeopardy (non bis in idem) is an integral part of the fundamental right to the principle of legality in criminal and administrative law matters (Article 25.1 of the Spanish Constitution), despite its lack of express mention in said constitutional provision, given its connection with the guarantees of specificity and legality of offenses.” It indicates that, within the scope of applicable ordinary legislation, it should be noted that, in accordance with Article 31 of Law 40/2015, of October 1, on the Legal Regime of the Public Sector: “Acts that have already been punished criminally or administratively may not be punished again in cases where there is an identity of the subject, the act, and the legal basis.” Therefore, it considers that the present disciplinary proceedings should be closed or, at least, suspended, and await the ruling of the Courts of Justice on the matter. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 11/46 For all the reasons stated above, “TME” requests: i. That Telefónica be declared not liable for the alleged infringement attributed to it in these proceedings, and that the present disciplinary proceedings be closed. ii. Alternatively, and in the event that the present disciplinary proceedings are not closed, that these proceedings be suspended and that the complainant be required to provide information on the status of the complaint filed, as well as the content of any ongoing criminal proceedings, in order to determine whether there is any prejudicial criminal matter. iii. Finally, should none of the above claims be upheld, the initially proposed sanction be reduced by virtue of the mitigating circumstances stipulated in Article 83 of the GDPR. EIGHTH: On October 14, 2025, the investigator issued the proposed resolution, which was notified electronically on October 20, 2025. The proposed resolution stated: “That the President of the Spanish Data Protection Agency sanction TELEFÓNICA MÓVILES ESPAÑA, S.A.U., with Tax Identification Number A78923125, for an infringement of Article 6.1 of the GDPR, as defined in Article 83.5 of the GDPR, with a fine of two hundred thousand euros (€200,000).” NINTH: On October 20, 2025, TME requested an extension of the deadline to submit arguments against the proposed resolution, and on October 23 of the same year, this extension was granted. On November 7, 2025, TME submitted a document that essentially reproduced the same arguments submitted in response to the agreement to initiate the proceedings. The content of this document is summarized in Legal Basis IV, "Response to the Arguments Submitted to the Proposed Resolution." From the actions taken in these proceedings and the documentation contained in the file, the following facts have been established: PROVEN FACTS FIRST: The claimant is a client of TME. Among the contracted services is mobile phone line number ***TELEPHONE.1. SECOND: On January 17, 2023, at the request of an unauthorized third party, TME issued a duplicate SIM card for line ***TELÉFONO.1, which was delivered to that third party and activated at 2:18 p.m., leaving the claimant without service. THIRD: The claimant repeatedly contacted TME requesting information regarding the issuance of the duplicate SIM card described in Finding Two. In its responses, TME stated the following: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 12/46 “…that the duplicate was requested at a store on January 17, 2023, at 2:18 p.m., and therefore in order to issue the duplicate, the customer had to present the ID of the holder at the store.” FOURTH: On January 19, 2023, the claimant requested a new duplicate SIM card to restore service to mobile phone line number ***TELEPHONE.1. To complete this process, the claimant signed a document labeled “SIM Card Replacement Agreement” provided for this purpose by TME, which is included in the case file and was submitted by the claimant. FIFTH: On June 21, 2023, the claimant filed a complaint with TME regarding the issuance of the duplicate SIM card described in Finding Two. In its response, dated June 23, 2023, TME reported that its systems contained two duplicate SIM card requests associated with line ***TELEPHONE.1, submitted on January 17 and 19, 2023. that they cannot be held responsible for potential bank fraud; and that they proceeded to refund the amount paid for the issuance of a new SIM card. TME adds that “the remaining information regarding these requests is stored and will be made available to the competent authorities during the investigation, through the channels established by Movistar for this purpose.” SIXTH: On December 21, 2023, in its response to the transfer of the claim formalized by this Agency, TME stated “that there is a request for a change of the SIM card ICC of the Claimant on January 17, 2023 through one of our authorized Points of Sale.” In the same document, regarding the documentation and data provided by the person who requested the duplicate SIM card described in the Second Proven Fact to verify their identity, and regarding the record in their systems of the identity verification checks, TME stated the following: “Telefónica, having reviewed its systems, has no record of any additional information in this regard.” SEVENTH: In its letter dated February 13, 2024, in response to the information request made by this Agency, TME reported the following: “First, regarding the SIM card replacement request dated January 17, 2023, Telefónica has no further information beyond what was already provided in the letter sent to this Agency on December 18, 2024. Second, regarding the SIM card replacement request dated January 19, 2023, we confirm that said request was made through one of our authorized physical stores, where, following the procedure already reported to this Agency for verifying customer identity, this verification was carried out through “***SYSTEM.1” (…). EIGHTH: TME has informed this Agency that requests for duplicate SIM cards made through physical stores or authorized points of sale of C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 13/46 TME, follow the following procedure: “(…)”. NINTH: On January 20, 2023, the complainant's wife filed a complaint with the National Police, the contents of which are hereby incorporated by reference for evidentiary purposes. According to this report, the complaint concerns fraudulent charges made to her bank account. The following statements are noteworthy: “That the complainant wishes to state that on January 17, 2023, her telephone service was interrupted. That upon contacting the O2 company, she was told it might be a problem with the SIM card. That after purchasing another SIM card, she still had no service and, upon contacting the company again, was told that the line was blocked due to possible fraud. As of today, I sent them an email requesting information about that block, but I haven't received a response yet. That the blocked phone number is ***PHONE.1, which is currently functioning normally. LEGAL BASIS I Jurisdiction In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR) and as established in Articles 47, 48.1, 64.2, and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to initiate and resolve this procedure. Likewise, Article 63.2 of the LOPDGDD stipulates that: “Proceedings handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, of this Organic Law, by the implementing regulations issued thereunder and, insofar as they do not contradict them, on a subsidiary basis, by the general rules on administrative procedures.” II Preliminary Issues Article 4.1) of the GDPR defines “personal data” as: “any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/46 C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 14/46 of that natural person.” For its part, Article 4.2 of the GDPR defines "processing" as: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; Furthermore, Article 4.7 of the GDPR establishes that the "controller" or "controller" is: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its appointment may be laid down by Union or Member State law. The processing of the claimant's personal data by TME without being authorized to do so has resulted in TME providing a duplicate of the claimant's SIM card to a third party without their consent and without verifying the third party's identity. TME carries out this activity in its capacity as data controller, since it is the one that determines the purposes and means of such activity, pursuant to Article 4.7 of the GDPR. III Response to the allegations submitted to the Commencement Agreement These allegations are addressed in the order presented by TME. PRELIMINARY ISSUE - CRIMINAL RESPONSIBILITY TME states that these events are currently the subject of a criminal investigation and, therefore, considers that the matter should not be resolved administratively until it is resolved through criminal proceedings. This, it states, is because the proven facts will bind the Agency with respect to a possible sanctioning procedure, in accordance with the provisions of Article 77.4 of the LPACAP (Law on Administrative Procedure and Common Administrative Procedure). It should be noted that this article establishes: “In sanctioning procedures, the facts proven by final criminal court rulings will bind the Public Administrations with respect to the sanctioning procedures they conduct.” However, it must be pointed out that the necessary three-part identity (of subject, fact, and grounds) does not exist between the administrative infraction being assessed and the possible criminal infraction or infractions that could arise from the alleged preliminary investigations carried out by a jurisdictional body. This is because the subject of the infringement would obviously not be the same – with respect to GDPR and LOPDGDD infringements. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/46 The data controller is TME, while the person criminally liable for any potential identity theft or fraud would be the third party who impersonated the claimant. Nor would the facts that could give rise to criminal proceedings, stemming from a complaint against the alleged impersonator for fraudulent bank charges, be the same as the legal basis protected by the GDPR and LOPDGDD. The legal interest protected in the criminal offenses whose commission would be investigated, if necessary, by the Investigating Court. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 15/46 LOPDGDD In this respect, the Judgment of the National Court of 27/04/2012 (rec. 78/2010) is very enlightening, in whose Second Legal Basis the Court rules in the following terms against the appellant's allegation that the AEPD has infringed article 7 of Royal Decree. 1398/1993 (the regulation that was in force until the entry into force of the LPACAP): “In this regard, Article 7 of Royal Decree 1398/1993, of August 4, on the procedure for exercising the power to impose sanctions, only provides for the suspension of the administrative procedure when the actual existence of criminal proceedings is verified, if it is considered that there is an identity of subject, act, and legal basis between the administrative infraction and the corresponding criminal infraction. However, for a criminal prejudiciality to exist, it is required that it directly condition the decision to be made or that it be essential to resolve the matter, conditions that are not met in the case under examination, in which there is a separation between the facts for which the sanction is imposed in the now appealed resolution and those that the appellant invokes as possible criminal offenses. Thus, even if criminal proceedings had been initiated in the present case, and for the facts now controversial, also criminal proceedings against the distribution company, the fact is that both the sanctioning conduct and the protected legal interest are different in each avenue (administrative and criminal). In the criminal sphere, the protected legal interest is possible document forgery and fraud, and in the administrative sphere, on the other hand, it is the right of the data subject to dispose of their personal data, therefore, such objection by the defendant must be rejected.” In consideration of the above, the issue raised by the defendant cannot succeed and must be rejected. I. ON THE FACTS THAT MOTIVATE THE INITIATION OF THIS AGREEMENT TO INITIATE SANCTIONING PROCEEDINGS - First. - Non-existence of commission of an infraction. Disagreement with the agreement to initiate the sanctioning proceedings. - Second. - The circumstances that have allowed third parties to circumvent the security policies implemented by Telefónica. TME states that the events that prompted the initiation of this disciplinary proceeding imply that the sales agent did not follow the established procedure for customer identification, which is appropriate for the management of duplicate SIM cards. There is no evidence to prove the lack of verification of the customer's identity. TME adds that it cannot be held responsible for the breaches by the personnel contracted by the data processors involved in these processes. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 16/46 and, furthermore, that these agents are victims of deception by the impersonating third parties who obtained the data subject's personal data previously and independently of TME. In this case, it is undisputed that TME processed personal data by issuing a duplicate SIM card to the claimant without their request, that is, without their involvement or knowledge. It is incumbent upon TME to demonstrate the lawfulness of this processing, in accordance with the principle of proactive responsibility (Article 5.2 of the GDPR), which imposes on the data controller the obligation to demonstrate compliance with the principles relating to processing regulated in Article 5.1 of the GDPR, including the principle of lawfulness. Thus, TME must be able to demonstrate that it acted with due diligence to correctly identify the person who requested the duplicate SIM card and that this person was indeed the registered user of the services. For this purpose, it is not sufficient to simply establish a procedure and state that it was followed. In this case, moreover, the protocol established by TME was not followed by the agent who handled the transaction. According to TME itself, this protocol included: (...) None of these requirements were met by TME in this case. It should be noted that from the moment a duplicate SIM card is given to someone other than the line owner or authorized person, the customer loses control of the line and the risks, damages, and losses multiply, with responsibility falling on the data controller. It should be pointed out that the High Court of Justice (SAN) - Administrative Chamber - of May 5, 2021, established that: “On the other hand, regarding the fact that we are dealing with fraud by a third party, as we stated in the SAN ruling of October 3, 2013 (Appeal No. 54/2012): “Precisely for this reason, it is necessary to ensure that the person contracting the service is who they claim to be and appropriate preventative measures must be adopted to verify the identity of a person whose personal data will be processed.” II. ON THE LEGAL BASIS. - First. Regarding the alleged infringement committed by Telefónica: absence of Typicity, unlawfulness, and culpability. - Second. Absence of culpability. Mistake of fact. In the present case, the existence of typicity, unlawfulness, and culpability in the infringing conduct of the entity responsible for processing the personal data, TME, is evident. As the data controller for issuing duplicate SIM cards, which decides on the purpose, content, and use of the personal data included in the processing, it has the obligation to act with greater C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 17/46 diligence when processing the issuance of duplicates, ensuring that it has the consent of the data subject, in order to avoid processing their personal data without consent. This condition imposes a special duty of diligence when using or processing personal data, insofar as it pertains to compliance with the duties established by data protection legislation to guarantee the fundamental rights and public freedoms of natural persons, the intensity of which is heightened by the relevance of the legal interests protected by those regulations and the professionalism of the controllers or processors, especially when they operate for profit in the data market; the National Court has also ruled in this sense in Judgment 392/2015, of November 17. In this regard, it is significant that the operator responsible for the processing does not duly justify the due diligence required of it in its conduct, nor does it demonstrate the adoption of the necessary safeguards to prevent the non-consensual processing of the personal data in question (the fraudulent issuance of a duplicate SIM card), which must be attributed to the negligent conduct of TME, as a third party used the claimant's personal data, bypassing the security measures to duplicate the SIM card. For this reason, this is a process where the due diligence exercised by the operator is essential to prevent this type of fraud and GDPR violations. This due diligence translates into establishing appropriate measures to guarantee that the person contracting the service is who they claim to be and that appropriate measures are implemented and maintained to comply with the principle of lawfulness. Recital 74 of the GDPR states: The controller's responsibility for any processing of personal data carried out by the controller or on behalf of the controller must be established. In particular, the controller must be obliged to implement appropriate and effective measures and must be able to demonstrate the compliance of processing activities with this Regulation, including the effectiveness of the measures. These measures must take into account the nature, scope, context, and purposes of the processing, as well as the risk to the rights and freedoms of natural persons. TME states that the requirement of culpability is not met in its actions and indicates that the SIM card duplicate was processed, in any case, as a result of acts of deception, manipulation, and illicit use of data by a third party, who allegedly deceived the sales agent into believing that they were the data subject or that they had the data subject's consent to make the request, having correctly identified themselves with the customer data in our systems. Therefore, TME states that it could never be considered culpable, as in this case, there was an unavoidable error. Indeed, the principle of culpability governs in Administrative Law (Article 28 of Law 40/2015, on the Legal Regime of the Public Sector, LRJSP), and therefore, the subjective or culpable element is an essential condition for establishing sanctioning liability. Article 28 of the LRJSP, “Liability”, states: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 18/46 “1. Only natural and legal persons, as well as, when a Law recognizes their legal capacity, groups of affected parties, associations and entities without legal personality, and independent or autonomous estates, who are responsible for such acts due to intent or negligence, may be sanctioned for acts constituting an administrative offense.” In light of this provision, liability for sanctions can be demanded based on intent or negligence, with the mere failure to observe the duty of care being sufficient in the latter case. The Constitutional Court has repeatedly declared that the principles of criminal law, including the principle of culpability, are applicable, with certain nuances, to administrative sanctions law, as both are manifestations of the State's punitive system (Constitutional Court Judgments 18/1987 and 150/1991), and that strict liability or liability without fault is not permissible in the administrative sanctions sphere. This principle excludes the possibility of imposing sanctions based solely on the result, without proving a minimum level of culpability, even for mere negligence (Constitutional Court Judgments 76/1990 and 164/2005). However, the method of attributing liability to legal entities does not correspond to the forms of intentional or negligent culpability that are attributable to human conduct. Therefore, in the case of offenses committed by legal entities, although the element of culpability must be present, it is necessarily applied differently than it is with respect to natural persons. According to Constitutional Court Ruling 246/1991, "(...) this distinct construction of imputability of the infringement to the legal entity arises from the very nature of the legal fiction to which these subjects respond. They lack the volitional element in the strict sense, but not the capacity to infringe the rules to which they are subject. This capacity to infringe, and therefore direct blameworthiness, derives from the legal interest protected by the infringed rule and the need for said protection to be truly effective, and from the risk that the legal entity subject to compliance with said rule must consequently assume" (in this sense, Supreme Court Ruling of November 24, 2011, Appeal No. 258/2009). To the foregoing, it must be added, following the judgment of January 23, 1998, partially transcribed in the Supreme Court judgments of October 9, 2009, Appeal No. 5285/2005, and of October 23, 2010, Appeal No. 1067/2006, that "although the culpability of the conduct must also be proven, it must be considered, in order to assume the corresponding burden, that ordinarily the volitional and cognitive elements necessary to assess it form part of the proven typical conduct, and that their exclusion requires proof of the absence of such elements, or, in its normative aspect, that the diligence required by the party alleging their non-existence has been employed; in short, the mere invocation of the absence of culpability is insufficient for exoneration from conduct that is typically unlawful." In connection with the above, we must again refer to Article 5.2 of the GDPR (principle of proactive responsibility), according to which the data controller is responsible for compliance with the provisions of paragraph 1—and, relevant to this case, the principle of lawfulness in relation to Article 6.1 of the GDPR—and C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 19/46 and be able to demonstrate such compliance. The principle of proactivity transfers to the data controller the obligation not only to comply with the regulations, but also to be able to demonstrate such compliance. Opinion 3/2010 of the Article 29 Working Party (WP29) – Working Party 173 – issued during the validity of the repealed Directive 95/46/EEC, but whose considerations are applicable today, states that the “essence” of proactive responsibility is the controller's obligation to implement measures that, under normal circumstances, ensure that data protection rules are met in the context of processing operations and to have documents available that demonstrate to data subjects and supervisory authorities what measures have been taken to achieve compliance with data protection rules. Article 5.2 is further developed in Article 24 of the GDPR, which obliges the controller to adopt appropriate technical and organizational measures “to ensure and be able to demonstrate” that processing is compliant with the GDPR. The judgment of the National Court of 17 October 2007 (appeal no. 63/2006) is fully applicable to this case. That judgment, after stating that entities whose business activities involve the continuous processing of customer and third-party data must observe an adequate level of diligence, states: “[...] the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. And in assessing the degree of diligence, special consideration must be given to the professional status of the individual, and there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data, rigor and meticulous care must be emphasized to ensure compliance with the relevant legal provisions. Regarding TME's conduct, it is considered to constitute negligence. As a depository of large-scale personal data, therefore, accustomed to or specifically dedicated to the management of customers' personal data, must be especially diligent and careful in its handling. That is to say, from the perspective of culpability, we are dealing with an excusable error since, with the application of appropriate technical and organizational measures, these identity impersonations could have been avoided. The defendant has invoked various arguments to justify the lack of culpability of its conduct. Basically, having a security policy aimed at ensuring that duplicate SIM cards are delivered to the owners of the telephone lines, which was circumvented by actions committed by a third party. However, there are numerous circumstances in the present case that lead to classifying TME's conduct as reckless and culpable in its failure to detect the fraud preventively, in such a way that it could have denied the request for the issuance of a duplicate SIM card that it received from an unauthorized third party and, therefore, refrain from processing the personal data of the claimant that involves issuing said card and delivering it to a different person C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 20/46 to its owner. The duplicate SIM card was processed at a physical store, (...). Once this verification was passed, the store gave the duplicate SIM card to the person. TME has not provided any evidence of compliance with this security protocol, any documentation (...) nor justification for the entries made in its information systems. It has not even informed this Agency of the point of sale where the transaction took place. Nor has it justified having carried out (...) The verification of the applicant's identity by the point of sale cannot be considered diligent. Regarding the method of identifying customers requesting a duplicate SIM card, TME also fails to demonstrate the existence of any specific procedures, (...). TME does not provide documentary evidence to prove that it correctly verified the identity of the applicant for the duplicate SIM card and their correspondence with the true owner of the telephone line, so the checks carried out are not proven. It is not enough to say that the sales agent (…). As indicated, Article 5.2 of the GDPR states that “The controller shall be responsible for compliance with paragraph 1 and be able to demonstrate such compliance (proactive responsibility),” since it is the controller, in compliance with the obligations imposed by this proactive responsibility, who must implement the necessary technical and organizational measures, as expressed in Articles 24 and 25 of the GDPR. The principle of proactivity transfers to the controller the obligation not only to observe the principles governing the processing, but also to be able to demonstrate such compliance. Article 5.2 of the GDPR is further developed in Article 24 of the GDPR, which obliges the controller to adopt appropriate technical and organizational measures “to ensure and be able to demonstrate” that the processing has been carried out in accordance with the GDPR. Thus, it can be concluded that the processing of personal data is carried out (i) without TME providing any guarantee that the applicant for the duplicate SIM card was the true owner of the line and, consequently, of the personal data; (ii) without knowing the reason for issuing the duplicate card; and (iii) without having carried out any checks to verify that issuing this duplicate was necessary for providing the services contracted by the claimant, who already had an active and functioning card. Therefore, it turns out that TME has not demonstrated that it verified the identity of the person who requested the duplicate SIM card that prompted these proceedings, thus calling into question the diligence employed by said entity to carry out that verification. It is significant, particularly regarding the applicable protocols, that the data controller does not thoroughly analyze the required diligence, shifting the responsibility to the agent, when the control over the veracity of the request for a duplicate SIM card, essential for the effective prevention of fraud, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 21/46 lies with TME itself. In short, there has been no proactive approach to effectively applying the principles of data protection. It is significant that, regarding the SIM card replacement requested by the claimant after the fraudulent replacement was activated, in order to recover services, TME provided all the documentation that it failed to provide regarding the replacement requested by the third party. Furthermore, despite the fraud being discovered through the claimant's contacts with this operator to report the incident, there is no record that TME conducted any investigation into the actions of the point of sale to determine the causes. Therefore, it is clear that the actions taken by TME are ineffective and insufficient, falling far short of the possibilities offered by current technology and failing to consider the evident risk that contracting the services it markets poses to the rights and freedoms of individuals. Consequently, TME must be held liable for the infraction committed due to its lack of due diligence. As a large-scale repository of personal data, and therefore accustomed to or specifically dedicated to managing the personal data of clients, it must be especially diligent and careful in its handling. Furthermore, given all the factual circumstances of this case, it cannot be said that the incident that occurred in the processing of the claimant's personal data was due to an attack carried out by a third party or that the fraud was undetectable. The fact that we are dealing with third-party fraud makes it necessary to ensure that the person to whom the duplicate SIM card is issued is who they claim to be, and appropriate preventative measures must be taken to verify the identity of a person whose data will be processed, as recognized in Legal Basis Seven of the SAN, SCA, of May 5, 2021 (“On the other hand, regarding the fact that we are dealing with third-party fraud, as we stated in the SAN of October 3, 2013 (Appeal No. 54/2012): “Precisely for this reason, it is necessary to ensure that the person contracting is who they claim to be, and appropriate preventative measures must be taken to verify the identity of a person whose personal data will be processed…”). Furthermore, it should be noted that the infringement attributed to the defendant is based on the lack of lawfulness in the processing of the claimant's personal data. In relation to this classification of the facts, we could cite Judgment 4660/2021, of December 13, 2021, which states that “the fraudulent intervention of a third party, who impersonates another person in an online transaction, does not preclude the possibility that the contracting company, which carries out the processing of the personal data, may have committed an infringement due to the lack of the necessary unequivocal consent required by Article 6 of Organic Law 3/2018, of December 5, since C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 22/46 that fraudulent intervention of a third party does not in itself imply that the contracting company acted with due diligence. The above does not mean that the contracting company is responsible for preventing an illegal or criminal act, such as the fraudulent use of an ID card by someone who is not its owner. However, it is indeed required of said contracting company, as a necessary precaution to avoid being accused of non-compliance with its obligations regarding the protection of personal data—both in terms of requiring the consent of the data subject and in relation to the principle of truthfulness and accuracy of the data—to implement control and verification measures aimed at ensuring that the person seeking to contract is who they claim to be, that is, that they match the holder of the ID card provided.” It is the issuance of a duplicate SIM card and its delivery to a third party that entails the processing of the personal data of its holder, insofar as it involves an identified and identifiable natural person. Thus, providing a duplicate SIM card is a process in which the diligence exercised by the operators is essential to prevent this type of fraud and guarantee the adequate protection of the rights and interests of customers, diligence which, as already explained, is called into question in the present case. In relation to all of the above, the doctrine established by the Supreme Court, Administrative Law Chamber, Third Section, in its Judgment of December 13, 2021 (Cassation Appeal No. 6109/2020), is of particular interest. This judgment analyzes a case of identity theft in an online transaction, in which the actions taken by the appellant to verify that it was contracting with the true data subject are questioned, and the appellant is sanctioned for the unlawful processing of the data subject's personal data. According to the order admitting the aforementioned cassation appeal, "the issue that presents objective legal interest for the formation of jurisprudence consists of interpreting the current personal data protection regulations in order to clarify whether the fraudulent intervention of a third party, who impersonates another person in an online transaction, allows for the exclusion of any infringement." by lack of the necessary unambiguous consent for the processing of personal data required by Article 6 of Organic Law 3/2018, of December 5, on the grounds that the contracting company acted with due diligence and in the belief that it was contracting with the true owner of such data.” This Judgment declares the following: THIRD.- The Court's response to the issue of legal interest raised in the order admitting the appeal. In response to the question raised in the order admitting this appeal, we must declare that the fraudulent intervention of a third party, who impersonates another person in an online contract, does not preclude the contracting company, which carries out the processing of personal data, from having C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 23/46 committed an infringement due to the lack of the necessary unambiguous consent that requires Article 6 of Organic Law 3/2018, of December 5, since that fraudulent intervention of a third party does not in itself imply that the contracting company has acted with sufficient diligence. The above does not mean that the contracting company is responsible for preventing an illegal or criminal act, such as the fraudulent use of a national identity document by someone who is not its holder. However, it is indeed required of said contracting company, as a necessary precaution to avoid being accused of non-compliance with its obligations regarding the protection of personal data—both in terms of requiring the consent of the data subject and in relation to the principle of truthfulness and accuracy of the data—to implement control and verification measures aimed at ensuring that the person seeking to contract is who they claim to be, that is, that they match the holder of the ID card provided.” Therefore, it is not a matter of attributing responsibility to TME for the mere finding of the unlawful processing of data, but for the lack of diligence in applying controls to ensure that the processing of the claimant's data was carried out with a legitimate basis. In short, the defendant issued a duplicate SIM card to a third party who was neither the account holder nor had proven that they were acting on their behalf, thus calling into question the diligence employed when carrying out the appropriate checks to verify the identity of the interested client, as well as the legitimacy of the request and the processing of the data. In light of the foregoing, it cannot be said that TME is subject to strict liability, thus violating the principle of culpability, or that there is no infringement due to the unlawful processing of the claimant's personal data. - Third. – Non-compliance with the principle of proportionality in the sanctions. Regarding the allegations concerning the severity of the sanction, it is appropriate to first address the allegation concerning the lack of proportionality of the proposed fine amount. In accordance with Article 83.1 of the GDPR, the fine imposed must be, in each individual case, effective, proportionate, and dissuasive. To guarantee these principles, TME's turnover is considered beforehand, which in the 2024 financial year amounted to ***AMOUNT.4 euros. Furthermore, the category of the infringement committed is taken into account, falling under the highest level of Article 83 of the GDPR, which the regulation sanctions with the greatest severity in paragraph 5, punishing the conduct with a maximum fine of 20 million euros or, in the case of a company, with a fine equivalent to a maximum of 4% of its annual turnover. According to the aforementioned provision, when establishing the maximum applicable amount, the higher of the two limits set by the regulation must be chosen. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 24/46 In this case, since it concerns a company whose turnover in 2024 amounted to ***AMOUNT.4 euros, the amount of the fine to be imposed will necessarily be between €0.00 and €176,476,480. Therefore, the fine proposed herein falls within the lower end of that range. The proposed sanction fulfills the deterrent function required by the GDPR, whose objective is to ensure that infringements are not repeated and to make regulatory compliance an effective priority, not merely a declaration, for the data controller. Therefore, the sanction is proportionate, appropriate, and necessary, fulfilling the objectives of Article 83 of the GDPR and guaranteeing a deterrent effect against future infringements. Furthermore, TME refers to the circumstances considered by this Spanish Data Protection Agency (AEPD) to quantify the sanction, specifically the negligence observed in its conduct, the infringements previously committed by the entity, and the connection of its activity with the processing of personal data. Regarding the negligence observed in Regarding its conduct, we refer to what is indicated in the previous point of this Legal Basis and to what is indicated in Legal Basis V, dedicated to determining the amount of the proposed fine. The same applies to the consideration of the previous infringements and the connection of TME's activity with the processing of personal data, which are also assessed in Legal Basis V. Furthermore, TME requests that the following mitigating circumstances be taken into account: It effectively resolved the issue that was the subject of the complaint: the line in question was subsequently recovered by the customer once they became aware of the facts, and the SIM card fee was refunded. Any measures taken by the data controller or processor to mitigate the damages suffered by the data subjects: it took appropriate action, strengthening the procedures established for this purpose. Moreover, these procedures are proven to be completely robust based on The figures presented. Adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42: it has signed the Self-Regulation Code of Conduct on data processing in advertising, which establishes an out-of-court dispute resolution system. None of the circumstances invoked are accepted. The respondent states that it effectively resolved the issue that is the subject of the complaint, enabling the complainant to recover the services, a matter that falls within the scope of its legal obligations. The admission that the respondent's effective resolution of the issue is a mitigating factor (Article 83.2 c) of the GDPR) partially negates the deterrent purpose of the sanction. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 25/46 Accepting TME's argument in a case such as this would introduce an artificial reduction in the penalty that should truly be imposed; the one resulting from considering the circumstances of Article 83.2 GDPR that must be assessed. Furthermore, as reflected in this document, TME took no action to resolve the situation created by the issuance of the fraudulent duplicate SIM card. It was the claimant who took the necessary steps to restore service to their mobile line by requesting a new SIM card. Regarding TME's claim that it took appropriate action, strengthening the established procedures, it should be noted that this entity has not reported any measures aimed at preventing similar situations in the future. On the contrary, it was specifically consulted on this matter and stated that it did not detect any incident in the processing of the duplicate SIM card that gave rise to these proceedings. no evidence has been found that it has adopted any reinforcement measures, beyond sending reminders of the same procedure. TME argues that its adherence to the Code of Conduct for Data Processing in Advertising should be considered a mitigating factor. The main objective of this Code, related to the receipt of unsolicited advertising, the exercise of rights related to advertising (such as the right to object), and the processing of data in advertising promotions or through advertising cookies, among others, is unrelated to the present case, and therefore cannot be considered a mitigating factor. - Fourth. - Estoppel and double jeopardy. TME indicates that in other sanctioning proceedings initiated against it for similar acts, such as sanctioning proceedings EXP202209359, EXP202207989, EXP202211479, or EXP202206971, the Agency TME has always appreciated, and in any case, the mitigating circumstance of having effectively resolved the incident that is the subject of the claim, something that is present in this case and is being overlooked (e.g., Sanctioning Resolution EXP202206971: “As mitigating circumstances: The defendant proceeded to block the line as soon as it became aware of the facts (Art. 83.2 c)”). Based on this, TME believes that the doctrine of estoppel has been violated. However, in this case, as already indicated, it was the actions taken by the claimant himself that led to the cancellation of the fraudulent SIM card. Furthermore, TME points out that it has already been sanctioned for the same facts that are being addressed in this proceeding, under number PS/00021/2021. TME considers that initiating a new sanctioning procedure, successively, without There is a ruling by the Courts of Justice, and on the same facts, it violates the principle of double jeopardy. It adds that this was considered in file No. EXP202104446, dated January 26, 2022, in which it was archived on the understanding that there was already a C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 26/46 sanctioning proceeding underway for the same facts, the wording of which was as follows: “On this issue, it should be noted that facts similar to those that are the subject of the complaint have been investigated by this Agency and sanctioned in the sanctioning proceeding PS/00021/2021, processed against the complainant, by resolution dated November 8, 2021, therefore, the initiation of a new sanctioning proceeding is not warranted.” Regarding this matter, besides the fact that the facts presented in the claim are not the same, it is important to highlight that these procedures aimed to analyze the procedures followed by TME to manage SIM card replacement requests within a specific period, identifying any vulnerabilities that may exist in the implemented operating procedures, to detect the causes of these cases, and to find areas of non-compliance, improvement, or adjustment, in order to determine responsibilities, reduce risks, and enhance the security of the personal data of the affected individuals. The sanctioning procedure PS/00021/2021 was challenged through administrative litigation, resulting in the judgment SAN of February 8, 2024 (appeal no. 2250/2021), in which the administrative appeal filed by “TME” was dismissed. On June 19, 2024, the First Section of the Administrative Chamber of the Supreme Court ruled that appeal no. 3244/2024, filed by Telefónica Móviles España SAU against the judgment of February 8, 2024, issued by the First Section of the Administrative Chamber of the National Court in administrative litigation no. 2250/2021, was inadmissible. The resolution of November 8, 2021, of the Director of the Spanish Data Protection Agency, issued in sanctioning procedure PS/00021/2021, imposing a fine of €900,000 for an infringement of Article 5.1.f) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, classified as very serious under Article 83.5.a) of said Regulation. IV Response to the Allegations Submitted to the Proposed Resolution The following is a response to the allegations submitted by TME, which are, in general terms, a reiteration of those submitted to the initial agreement and addressed in the proposed resolution, as reproduced in the preceding Legal Basis. PRELIMINARY ISSUE I.- ON THE INITIATION OF THE SANCTIONING PROCEEDINGS Telefónica reiterates each and every one of the allegations made in the Initiation Agreement and states that it has sufficient and appropriate measures in place, as determined by the GDPR, both for changes of line ownership and for SIM card replacement requests. Telefónica also states that it is another victim of fraudsters and that a zero-fraud result is not required in light of the principles established in the GDPR and the obligations of the Data Controller. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 27/46 Regarding the aforementioned allegations made by Telefónica, it is important to note that these were already addressed in the previous Legal Basis. PRELIMINARY ISSUE II.- ISSUE OF CRIMINAL PREJUDICIALITY With respect to the issue of criminal prejudiciality, TME states that it requested the suspension of the proceedings in order to determine the status of the complaint filed by the affected party and, above all, to ascertain the content of any ongoing criminal proceedings. Telefónica cites Judgment No. 2249/2016 of the Administrative Chamber of the Supreme Court, dated October 18, 2016, in which, despite the fact that the administrative and criminal proceedings concerned different taxes, the exception of criminal prejudiciality was upheld. Therefore, TME believes that the current sanctioning proceedings should be suspended until the criminal courts rule on the matter. In the judgment cited by TME, there is a triple identity of subject, act, and legal basis, which is not present in this case, and we reiterate what was stated in the response to the objections to the initiation agreement. In this regard, the arguments presented in the previous Legal Basis, in response to the objections to the initiation, are relevant. In that section, it was noted that in this case, the required triple identity for suspending the administrative procedure due to its connection with the proceedings in the criminal jurisdiction is not present: - The offending party would obviously not be the same – with respect to the GDPR infringements, Telefónica is responsible, while the criminally responsible party for any potential crime of identity theft or fraud would be the third party who impersonated the claimant. Nor would the legal basis be the same: while the legal interest protected by the GDPR and the LOPDGDD is the fundamental right to the protection of personal data, the legal interest protected in the criminal offenses whose commission would be investigated by the Investigating Court would be civil status, assets, etc. In this regard, the Judgment of the National Court of April 27, 2012 (appeal no. 78/2010), already cited in Legal Basis III, is very enlightening. In light of the foregoing, the issue raised by the respondent cannot succeed and must be rejected. I. ON THE FACTS THAT MOTIVATE THE INITIATION OF THIS AGREEMENT TO INITIATE THE SANCTIONING PROCEEDINGS C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 28/46 FIRST. - NO COMMISSION OF AN INFRACTION. DISAGREEMENT WITH THE AGREEMENT TO INITIATE THE SANCTIONING PROCEEDINGS. VIOLATION OF THE PRINCIPLE OF PRESUMPTION OF INNOCENCE. Telefónica states that the fact that it did not make a verification call and does not have a recording does not mean that the sales representative did not follow the established protocol regarding customer identification. It asserts that the Agency has not rebutted Telefónica's presumption of innocence, nor demonstrated guilt, responsibility, or unlawfulness. To this end, TME, in its defense, refers to the set of security measures it has adopted, which are the minimum required of any organization with the characteristics and in the context in which a telecommunications operator operates. In this regard, the mere existence of a security policy cannot justify compliance with the principle of lawfulness stipulated in Article 6.1 of the GDPR. In addition to existing, these measures must be effective, allowing the data controller to demonstrate that the data processing carried out is lawful. Otherwise, the measures adopted are ineffective, especially if they are not respected by the entity that has implemented them. In short, the defendant cannot exonerate itself from responsibility by simply appealing to the existence of minimal measures and the deception to which companies and their sales representatives are subjected by impersonators. Furthermore, it is incomprehensible that TME is questioning facts that have been sufficiently proven, even acknowledged by the entity itself. Facts with sufficient force to overturn the presumption of innocence. The proceedings have demonstrated both the unlawful processing of data and TME's responsibility for carrying it out. It is also incomprehensible that TME is attempting to have this Spanish Data Protection Agency (AEPD) classify as diligent an action in which a duplicate SIM card of the complainant was provided to a third party, without their consent and without verifying the identity of said third party. It is worth reiterating what was stated in the National High Court ruling of October 29, 2024, appeal no. 1824/2021, cited above, which states that “…it must be emphasized, in relation to the technical and organizational measures, that we are not dealing with a merely formal requirement, but a substantive one. In this sense, and in line with what has been stated above, as the Supreme Court ruling of February 15, 2022 (Appeal No. 7359/2020) points out, “It is not enough to design the necessary technical and organizational means; their correct implementation and appropriate use are also necessary, so that liability will also apply to the lack of due diligence in their use, understood as reasonable diligence considering the circumstances of the case,” which does not imply that an obligation of result is required.” SECOND. - TELEFÓNICA'S ROLE AS AN INJURED PARTY. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 29/46 Telefónica reiterates the arguments made in the initial agreement, emphasizing the technical and organizational measures that are adequate and relevant and that operators must address third parties whose intention is to commit identity theft. It points out that Telefónica cannot be held responsible for the isolated and exceptional operational breaches that may have occurred by personnel contracted by the data processors involved in these processes. Regarding the previous arguments raised by Telefónica, it is important to note that these were already addressed in the preceding Legal Basis. In this section, Telefónica requests that the sanctioning resolutions published by the Agency through its website, which are publicly accessible and can be accessed by unwanted individuals who could acquire full knowledge of its operations and security protocols, be published in an anonymized form. Regarding the publication of resolutions, Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) establishes that “The Spanish Data Protection Agency shall publish the resolutions of its Presidency that declare whether or not there are grounds for exercising the rights recognized in Articles 15 to 22 of Regulation (EU) 2016/679, those that conclude sanctioning and warning proceedings, those that close preliminary investigations, those issued with respect to the entities referred to in Article 77.1 of this Organic Law, those that impose precautionary measures, and any others provided for in its Statute.” Article 11 of the Statute of the Spanish Data Protection Agency, approved by Royal Decree 389/2021 of June 1, provides as follows: “Article 11. Transparency and Publicity. 1. The Spanish Data Protection Agency shall publish on its website the resolutions of its Presidency that determine whether or not the rights recognized in Articles 15 to 22 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, have been exercised; those that conclude the complaint procedures; those that close the preliminary investigation proceedings; those that impose sanctions with a warning on the entities referred to in Article 77.1 of Organic Law 3/2018 of December 5; and those that impose measures.” precautionary measures. 2. Without prejudice to the provisions of Law 19/2013, of December 9, on transparency, access to public information and good governance, all information that the Presidency considers relevant and that contributes to the better performance of its functions will also be published on the website. Therefore, the obligation to publish the resolutions issued by this Agency is established as a general rule, and this publication is carried out on the AEPD website. In this regard, without prejudice to the corresponding anonymization of the personal data of the individuals appearing in the resolution, it is not possible C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 30/46 to omit any reference to the respondent in the resolution, since, on the one hand, the respondent is not considered an individual and, on the other hand, in the interest of the public, which allows for knowledge of the criteria used by this authority, in addition to the objective of preserving its transparency in its actions. The publication of certain resolutions of the Spanish Data Protection Agency (AEPD) is mandated by the provisions of Article 50 of the Spanish Data Protection Act (LOPDGDD). Unlike other regulatory areas where the publication of a sanctioning resolution is expressly provided for as a sanction—for example, Articles 304 and 308 of Royal Legislative Decree 4/2015, of October 23, which approves the consolidated text of the Securities Market Law—in data protection matters, the regulation that mandates the publication of certain resolutions does not classify publication as a sanction. The purpose of publication is not to publicly sanction the offender for their conduct, but rather to provide transparency and general public awareness of the activities carried out by the Spanish Data Protection Agency (AEPD). Furthermore, the purpose of publishing resolutions is easily understood when one considers that those published are not only those that may result in sanctions, which are the ones that conclude sanctioning procedures, but also include resolutions concerning rights procedures, resolutions concerning warning procedures, and resolutions that close preliminary investigations, in addition to those established by the Statute. Thus, it is a guarantee for those subject to administrative action, as established in Article 45 of the LPACAP (Law on the Common Administrative Procedure of Public Administrations). Where the Law does not expressly define publication as a sanction, nor can it be inferred from its legal nature, we cannot interpret it as such either. Therefore, the publication of the administrative resolution is required, as mandated by the Law, which literally states that it "shall be published." By publishing the resolution in accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), the general interest entrusted to the AEPD (Spanish Data Protection Agency) is fulfilled. However, this must always be properly anonymized and excluding from the resolution any confidential or intellectual property secrets. On this matter, the National Court issued its Order of January 13, 2022, stating the following: “Therefore, in the present case, the appealed sanctioning resolution is published, pursuant to Article 50 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and the guarantee of digital rights, which provides: “The Spanish Data Protection Agency shall publish the resolutions of its Presidency that declare whether or not there are grounds for addressing the rights recognized in Articles 15 to 22 of Regulation (EU) 2016/679, those that conclude the complaint procedures, those that close the preliminary investigation proceedings, those that sanction with a warning the entities referred to in Article 77.1 of this Organic Law, those that impose precautionary measures, and C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 31/46 and any other obligations stipulated in its Statute. That is, the aforementioned provision obliges the Spanish Data Protection Agency (hereinafter AEPD) to publish its resolutions once they have been notified to the interested parties. Therefore, the suspension of the publication of the sanctioning resolution on the AEPD website must be rejected, as there is a clear public interest in publicizing the AEPD's resolutions on its website, in order to preserve the transparency of the AEPD's activities and, ultimately, the protection of the right to data protection through knowledge of the criteria for applying data protection regulations. It should be recalled, as the Supreme Court, Third Chamber, in its Order of March 31, 2015, pointed out, that “the Public Administration operates under a regime of publicity of its acts in general and, specifically, all the more so when so established by the regulations governing each sector.” II. ON THE LEGAL GROUNDS. FIRST. - ON THE ALLEGED INFRINGEMENT COMMITTED BY TELEFÓNICA: LACK OF LEGALITY AND UNLAWFULNESS. TME considers that the principle of legality is being violated since the conduct carried out by Telefónica cannot be subsumed under the typical action with which it is charged, this being an alleged unlawfulness in the processing of customer data due to the lack of a legitimizing basis for it, and points out that the legal basis that legitimizes the processing of the claimant's personal data is none other than the performance of the contract, Article 6.1 b) of the GDPR. TME points out that, taking into account both Telefónica's allegations and the Agency's own arguments, the processing carried out by this party is lawful and the sanctioning proceedings should therefore be closed, as the action is not a typical one. Likewise, it states that Telefónica's conduct does not fall under the provision whose infringement is alleged and cannot be considered unlawful. Telefónica maintains that it has acted at all times in good faith and with a well-founded belief that excludes any culpability, since, as long as a person identifies themselves as the holder of a contract, providing their identification data and national identity document, and requests a duplicate SIM card to be able to use the service, Telefónica can do nothing other than provide it, since otherwise it would be in breach of current regulations on electronic communications. According to TME, its conduct could never be considered culpable, as In this case, an invincible mistake of fact occurred, and it is noted that, in this specific instance, where identity theft had to take place, the invincible mistake of fact arises from the moment the salesperson was deceived and believed in good faith that they were interacting with a legitimate person, when in reality they were being impersonated by a third party. In this case, Telefónica states that, according to the established procedure, the customer would have identified themselves with the correct information for the duplicate request. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 32/46 that we would be dealing with an invincible mistake of fact, where the unlawfulness of the conduct was unknown, and the proceedings should be dismissed, as Telefónica's culpability could not be determined. On these matters, we can only refer to the arguments presented in the legal basis. The previous response to the allegations made at the start of the proceedings was similar to those previously stated. Furthermore, it should be noted that the error that it claims to have committed cannot in any way be considered to exclude its liability, since, according to established jurisprudence, such an error cannot be deemed to exist when it is attributable to the party who suffers it or could have been avoided with greater diligence. In another matter, Telefónica invokes the execution of the telecommunications service contract between the claimant and the operator as the basis for legitimizing the duplication of the SIM card. However, in cases such as this, the data processing involved in issuing a duplicate SIM card is not necessary for the provision of services, which were being provided normally. It is precisely the issuance of this duplicate and its delivery to a third party that causes the service disruption for the account holder, forcing them to request a new card to restore service. SECOND. - PROPORTIONALITY OF THE SANCTION 1. Regarding the aggravating circumstances considered but not applicable to the specific case: a) “The evident link between the defendant's business activity and the processing of personal data of clients or third parties (Article 83.2.k of the GDPR in relation to Article 76.2.b of the LOPDGDD).” With respect to this aggravating circumstance, TME points out that there would have to be a large number of data subjects affected by the potential infringement. In other words, the GDPR does not establish that this aggravating circumstance must be automatically applied when a controller generally processes a large or “massive” amount of personal data, but rather based on the number of potential data subjects. And it understands that this position is corroborated by the European Data Protection Board, which endorsed and therefore adopted the content of the Guidelines on the application and imposition of administrative fines for the purposes of Regulation 2016/679 adopted by the Article 29 Working Party on 3 October 2017, which clearly stipulate that the factors provided for in Article 83.2 of the GDPR must be assessed in combination, that is, in what concerns us here, the number of data subjects along with the potential impact on them. Similarly, Recital 75 of the GDPR stipulates that, in order to determine the degree of damage that a possible data protection infringement may cause, consideration must be given, among other aspects, to whether “the processing involves a large amount of personal data and affects a large number of data subjects.” C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 33/46 This means, contrary to the interpretation made by the Agency on a recurring basis, that the aggravating circumstance should only be applied if the infringement affects many interested parties. TME questions whether the connection of its activity with the processing of personal data can be taken into account when determining the fine, pointing out that this factor in determining the severity of the penalty is related to the number of interested parties affected by the infringement and the degree of damages that may have been caused. However, nothing in the wording of the regulation allows for this conclusion. The applicable rule is clear when it establishes that, in deciding on the imposition of a fine and its amount, consideration will be given to “the connection of the offender's activity with the processing of personal data,” as this Spanish Data Protection Agency (AEPD) has been doing when the offending party carries out an activity that involves a high volume of data processing and the infringement is related to its main activity. The National Court also considered this in its Judgment of September 13, 2024, when it stated the following: “In the case at hand, the appellant achieved a turnover exceeding 46 million euros in 2018 and has more than 600 employees. Therefore, the imposed sanction cannot be considered disproportionate given the circumstances, taking into account its turnover and its connection to the processing of personal data, considering the number of people employed by UST and its activity.” b) the circumstances outlined in Article 83.2(e) of the GDPR, relating to any infringement committed by the controller or processor: TME states that this sanctioning procedure is related to a specific case, a complaint filed with the Agency, and that non-compliance with the procedures is not the norm, and that it should be considered an isolated and specific case. These issues are addressed in Legal Basis VII, dedicated to determining the amount of the fine imposed in this case. The proposed sanction fulfills the deterrent function required by the GDPR, whose objective is to ensure that infringements are not repeated and to ensure that regulatory compliance is an effective priority, not merely a declaration, for the controller. Therefore, the sanction is proportionate, appropriate, and necessary, fulfilling the objectives of Article 83 of the GDPR and ensuring a deterrent effect against future infringements. Furthermore, TME refers to the circumstances considered by this Spanish Data Protection Agency (AEPD) to quantify the sanction, specifically the negligence observed in its conduct, the infringements previously committed by the entity, and the connection of its activity with the processing of personal data. Regarding the negligence observed in its conduct, we refer to what is indicated in the previous point of this Legal Basis and to what is indicated in Legal Basis VII, dedicated to determining the amount of the proposed fine. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 34/46 The same applies to the consideration of the aforementioned infringements and the connection between TME's activity and the processing of personal data, which are also assessed in the aforementioned Legal Basis VII. 2. Regarding the mitigating circumstances that the Agency did not consider in the proposed resolution: “b) Intentionality or negligence in the infringement: as noted, the requirements of intent in the alleged commission of the infringement or negligent conduct are not met in this case, since it was a third party who processed the Complainant's personal data without their consent after obtaining it unlawfully. c) Any measures taken by the controller or processor to mitigate the damages suffered by the data subjects: Telefónica took the appropriate actions, strengthening the procedures established for this purpose. j) Adherence to codes of conduct pursuant to Article 40 or to certification mechanisms approved pursuant to Article 42: Telefónica has signed the Self-Regulation Code of Conduct on data processing in advertising, which is an out-of-court dispute resolution system for resolving disputes that arise between citizens. and the entities adhering to the code regarding data processing carried out within the scope of advertising activity.” Regarding the mitigating circumstances invoked by TME, it should be reiterated that these have already been rejected in the previous Legal Basis, to which reference should be made again. V Breach of Obligation Issuing a duplicate SIM card and delivering it to a third party constitutes the processing of the holder's personal data, since any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier, is considered an identifiable natural person (Article 4.1 of the GDPR). The SIM card identifies a telephone number, and this number, in turn, identifies its holder. Issuing a duplicate SIM card necessarily implies the processing of personal data, as it is carried out on the line and the holder's identity. As can be seen in the proceedings, the data processing under analysis has involved the use of the claimant's data relating to name, surname, national identity document number, and mobile phone number, among others. The reference to the phenomenon known as SIM swapping and its potential consequences is made in order to assess the scope and nature of the alleged infringement , considering the repercussions that such practices may have on the rights of the data subject. In this regard, the National Court, in its judgment of May 13, 2024, Rec. 0002336/2021, establishes that “(…) in the first phase of this type of fraud, the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 35/46 impersonator fraudulently obtains the client's online banking login credentials, but lacks the verification code, the second authentication factor, to be able to carry out any transaction. The moment they obtain the duplicate SIM card, they also gain access to this second authentication factor and, therefore, from that moment on, can perform any asset disposal they wish.” Regarding the access to the customer's personal data involved in delivering the card to a third party, it is necessary to point out that access to a duplicate SIM card which identifies its holder, falls under the definition of personal data in Article 4.1) of the GDPR, as indicated in the Initial Agreement. In this regard, Judgment 595/2024 of the National Court, dated February 8, 2024, states: “We must begin by noting that the issuance of a duplicate SIM card involves the processing of the holder's personal data, since, according to Article 4.1 of the GDPR, an identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier. The SIM card is inserted into the mobile terminal. It is a small, physical smart card containing a chip that stores the subscriber's service key used to identify themselves to the network; that is, the customer's MSISDN (Mobile Station Integrated Services Digital Network) mobile line number, as well as the subscriber's IMSI (International Mobile Subscriber Identity) personal identification number.” mobile-), but it can also provide other types of data such as information about the phone directory or the call and message log. And as highlighted in the appealed resolution, since 2007, in Spain, in accordance with the Sole Additional Provision of Law 25/2007, of October 18, on the retention of data relating to electronic communications and public communications networks, it is required that the holders of all SIM cards, whether prepaid or contract, be duly identified and registered. Therefore, when obtaining a duplicate SIM card, the person requesting it must also identify themselves and their identity must match that of the holder. The defendant is accused of committing an infringement by violating Article 6 of the GDPR, "Lawfulness of processing," which specifies in paragraph 1 the circumstances under which the processing of third-party data is considered lawful: "1. Processing will only be lawful if at least one of the following conditions is met: a) the data subject has given consent to the processing of their personal data for one or more specific purposes; b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract; c) processing is necessary for compliance with a legal obligation to which the controller is subject; d) processing is necessary to protect the vital interests of the data subject or of another natural person; C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 36/46 e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. The provisions of paragraph 1(f) shall not apply to processing carried out by public authorities in the exercise of their functions. In the present case, it is established that TME issued and provided a duplicate of the claimant's SIM card to a third party without their consent and without verifying the third party's identity. Therefore, the respondent did not verify the identity of the person who requested the duplicate SIM card and did not take the necessary precautions to prevent these events from occurring. On December 21, 2023, TME informed this Agency of the channel through which the duplicate SIM card was processed and the method of identifying the person who requested it, stating the following: "Telefónica reports that a request for an ICC change of the claimant's SIM card was made on January 17, 2023, through one of its authorized points of sale." Regarding the documentation and data provided by the person who requested the SIM card to prove their identity and the completion of the identity verification checks: Telefónica, having reviewed its systems, has no record of any additional information in this regard. Based on the above, in the case analyzed, although the respondent only states that the duplicate was issued in person, it does not prove whether it followed the procedure it itself established, which, according to its response to this Agency dated December 21, 2023, consists of: - (...). In light of the above, the respondent fails to prove that the aforementioned procedure was followed, having provided no documentation proving that the duplicate was issued in accordance with the previously established procedure, stating only that the duplicate was issued in accordance with it. It is undisputed that TME issued a duplicate SIM card at the request of a third party, which constitutes unlawful processing, and this absence The lack of accreditation regarding the verification of the applicant's identity prevents any assessment of due diligence on the part of TME. In this regard, it is worth recalling that, in accordance with the principle of proactive responsibility established in Article 5.2 of the GDPR, the data controller is not only responsible for compliance with the principles established in Article 5.1, but must also be able to demonstrate such compliance. Since the proper processing of the personal data of the complainant has not been demonstrated, it cannot be justified that the processing is lawful. This constitutes, without prejudice to the possibility of demonstrating it during these proceedings, a presumed violation of the principle of lawfulness of processing recognized by Article 6.1 of the GDPR, a fundamental pillar in the field of personal data protection. Based on the foregoing As stated above, in the case under analysis, the diligence exercised by the respondent in identifying the person who requested a duplicate SIM card is called into question. Based on the available evidence, it is considered that the respondent's conduct violates Article 6.1 of the GDPR, constituting the infringement defined in Article 83.5(a) of Regulation 2016/679. In this regard, Recital 40 of the GDPR states: “(40) For processing to be lawful, personal data must be processed with the data subject’s consent or on another legitimate ground established in accordance with the law, whether in this Regulation or under other Union or Member State law to which this Regulation refers, including the need to comply with a legal obligation to which the controller is subject or the need to perform a contract to which the data subject is a party or in order to enter into a contract…” measures at the request of the data subject prior to the conclusion of a contract.” VI Classification and assessment of the infringement for limitation purposes The infringement is classified under Article 83.5 of the GDPR, which considers the following as such: “5. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher: The basic principles for processing, including the conditions for consent pursuant to Articles 5, 6, 7 and 9.” For the purposes of the statute of limitations for this infringement, the LOPDGD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) classifies in its Article 72.1 as a very serious infringement, in which case the statute of limitations is three years, “b) The processing of personal data without any of the conditions for lawful processing established in Article 6 of Regulation (EU) 2016/679 being met.” VII Fine. Determination of the amount Determining the appropriate fine in this case requires compliance with the provisions of Articles 83.1 and 2 of the GDPR, which, respectively, stipulate the following: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 38/46 “1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for infringements of this Regulation referred to in paragraphs 4, 9, and 6 is, in each individual case, effective, proportionate, and dissuasive. 2. Administrative fines shall be imposed, depending on the circumstances of each individual case, either in addition to or as an alternative to the measures provided for in Article 58(2)(a) to (h) and (j). In deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to: (a) the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered; (b) the intentionality or negligence of the infringement; (c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures implemented pursuant to Articles 25 and 32; (e) any prior infringements committed by the controller or processor; (f) the degree of cooperation with the supervisory authority with a view to remedying the infringement and mitigating its possible adverse effects; (g) the categories of personal data affected by the infringement; (h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement; (i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42, and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.” Within this section, the LOPDGDD (Spanish Data Protection Law) stipulates in its Article 76, entitled “Sanctions and Corrective Measures”: “1. The sanctions provided for in paragraphs 4, 5 and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the severity of the sanction established in paragraph 2 of that Article.” 2. In accordance with Article 83.2.k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the infringement. b) The connection between the infringer's activity and the processing of personal data. c) The benefits obtained as a result of committing the infringement. d) The possibility that the data subject's conduct may have induced the commission of the infringement. e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity. f) The impact on the rights of minors. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 39/46 g) Having a data protection officer, where not mandatory. (h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party. 3. The adoption, as appropriate, of the remaining corrective measures referred to in Article 83.2 of Regulation (EU) 2016/679 may be adopted, either as a complement or alternative. (3) The controller or processor may also submit to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party. (4) The controller or processor may also adopt, as a complement or alternative, the remaining corrective measures referred to in Article 83.2 of Regulation (EU) 2016/679. (5) The controller or processor may voluntarily submit to alternative dispute resolution mechanisms in cases where disputes arise between them and any interested party. In this case, considering the seriousness of the infringement, and paying particular attention to the consequences it has on the complainant, a fine is warranted. The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with Article 83.1 of the GDPR. To guarantee these principles, the turnover of the complainant is considered beforehand, which in the 2024 financial year amounted to €4. First, the category of the infringement committed is taken into account, falling within the highest level of Article 83 of the GDPR, which the regulation sanctions with the greatest severity in paragraph 5, punishing the conduct with a maximum fine of €20 million or, in the case of a company, with a fine equivalent to a maximum of 4% of its annual turnover. According to the aforementioned provision, when establishing the amount The maximum applicable fine must be the higher of the two limits established by the regulation. In this case, since the company's turnover in 2024 amounted to €0.00, the fine to be imposed will necessarily be between €0.00 and €176,476,480. In accordance with the aforementioned provisions, for the purpose of determining the amount of the fine to be imposed on the entity named as responsible for the infringement of Article 6.1 of the GDPR, as defined in Article 83.5(a) of the GDPR, the following factors are considered relevant in this case: 1. The following circumstances are taken into consideration as determining the level of seriousness of the infringement: Article 83.2(a) of the GDPR: “the nature, seriousness and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage and loss they have suffered.” Nature of the infringement: Article 83.5 encompasses several different types of conduct. In this case, the infringed provision affects a basic principle of the right to the protection of personal data, as it underpins the lawfulness of data processing and its violation entails a significant risk to the rights of data subjects. In this case, TME's conduct has directly caused harm to the C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 40/46 legal interest protected by Article 6 of the GDPR, preventing its effective application and the objective it seeks to protect. Seriousness of the infringement: Nature and purpose of the processing: Evaluate the seriousness of these aspects of the processing of Personal data processing requires consideration of the context in which it is carried out. The data processing carried out in this case is for the purpose of issuing a SIM card, necessary for TME to provide the services contracted by its owner. If this card is requested by a third party and the entity does not fulfill its obligations to prevent this irregularity, the end result is the delivery of the card to a person not authorized to use it and, consequently, the possibility that a third party may access various information of the true cardholder, which can be used for fraudulent purposes. This is what happened in the present case, in which a third party used the fraudulently obtained duplicate SIM card to withdraw funds from the claimant's bank accounts. This is the phenomenon known as “SIM swapping,” widespread in the current context and well known to TME. Based on this context, the processing carried out by TME, considering its nature and purpose, entails significant risks for the owner of the personal data. And it cannot be overlooked that said processing Data processing is carried out within the framework of the aforementioned operator's main and core business activity, which is conducted for profit. Scope of processing: The assessed infringement is committed through the unlawful processing of the personal data of a single data subject, the complainant, as considered in the following grading factors. However, it is important to consider that TME is a telephone company that operates nationwide and that the infringement is a direct consequence of the weaknesses in the mechanisms designed by TME for processing online SIM card replacement requests and of non-compliance with the established procedures. Therefore, the risk this entails increases the number of potentially affected parties. The relationship between the infringement committed and the allocation of resources that can be required of TME to prevent this type of unlawful activity must be analyzed based on the actual risk and the circumstance related to its national scope of operations. Number of data subjects: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 41/46 The sanctioned infringement is a consequence of the unlawful processing of the personal data of a single data subject, the complainant. The level of harm suffered by the complainant: In accordance with Recital 75 of the GDPR, the level of harm suffered refers to physical, material, or non-material damages. In this case, the harm suffered by the complainant cannot be considered marginal. On the one hand, the complainant was deprived of the service they had contracted with TME and, on the other hand, suffered bank fraud as a direct consequence of the sanctioned infringement, which, as has been stated, is committed not only through the data processing necessary to issue the duplicate SIM card, but also through the data processing consisting of the communication of the complainant's data to a third party, resulting from the delivery of the duplicate SIM card to said third party. Third. In cases like this, the data subject loses control of their personal data, so the harm could persist for an indefinite period. Article 83.2.b) of the GDPR: “Intentional or negligent infringement.” TME's conduct demonstrates gross negligence, due to a breach of the duty of care required by law, beyond what might be considered a neutral factor associated with the subjective element of culpability. This conclusion stems from objective elements of TME's conduct, obtained based on all the factual circumstances detailed in the preceding Legal Grounds, which clearly demonstrate the lack of rigor observed in the actions of the aforementioned entity in ensuring that the request originated from the claimant. The processing of personal data is carried out (i) without TME providing any guarantee that the applicant for the duplicate SIM card was the true owner of the line and, consequently, of the data personal data; and (ii) without having carried out any checks to verify that issuing this duplicate was necessary for the provision of the services contracted by the claimant, who already had an active and functioning SIM card. As a result, the data in question was processed without any legal basis. The ultimate consequence of all this was that TME validated the request, activated the SIM card and delivered it to a third party without any reliable evidence of the identity of the person making the request, to ensure that the latter corresponded to the owner of the services and the personal data. Also related to the degree of diligence that TME is obliged to exercise in complying with the obligations imposed by data protection regulations, the National High Court ruling of 17/10/2007 can be cited. Although it was issued before the GDPR came into effect, its pronouncement is perfectly applicable to the case we are analyzing. The ruling, after alluding to the fact that entities whose activities involve the continuous processing of customer and third-party data must exhibit an appropriate level of diligence, specified that “(...) the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. And in assessing the degree of diligence, special consideration must be given to the professional status of the individual, and there is no doubt that, in the case now under examination, when the appellant's activity involves the constant and extensive handling of personal data, rigor and meticulous care must be emphasized to comply with the relevant legal provisions.” Article 83.2.g) of the GDPR: “the categories of personal data affected by the infringement.” Apart from the personal data whose processing is necessary for issuing the duplicate card, the evident risks cannot be overlooked that delivering this duplicate to a third party could allow them access to special categories of data or other sensitive information, such as the complainant's financial information, as demonstrated in this case. 2. The following factors are considered aggravating circumstances: Article 83.2.d) of the GDPR: “the degree of responsibility of the controller or the processor, taking into account the technical and organizational measures they have implemented pursuant to Articles 25 and 32.” The aforementioned provisions, both Article 25 and Article 32 of the GDPR, oblige the responsible entity to take into account “the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks of varying likelihood and severity of processing for the rights and freedoms of natural persons” when implementing appropriate technical and organizational measures to ensure the effective application of the principles of data protection, in this case, the principle of lawfulness of processing, and to guarantee a level of security appropriate to the risk. In light of these provisions, the actions taken by TME have proven clearly ineffective and insufficient, falling far short of the possibilities offered by current technical developments and failing to consider the evident risk that the provision of its services poses to the rights and freedoms of individuals. In this regard, its high business volume means that the level of demand for incorporating the tools and functionalities that the state of the art offers at any given time is high. The weaknesses already expressed regarding TME's establishment of a security policy to prevent the impersonation of its clients, guaranteeing the principle of lawfulness in data processing, call into question the robustness of the measures adopted under Articles 25 and 32 of the GDPR, which aggravates its conduct in this specific case. It should be noted that the protocol established by TME for SIM card replacement or duplication, C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 43/46 (…). Thus, it can be concluded that the infringement has systemic implications and, therefore, may affect, even at different times, additional data subjects who have not submitted complaints to this supervisory authority. Article 83.2(e) GDPR: “Any prior infringement committed by the controller or the processor.” Article 83.2 of the GDPR and Article 76 of the LOPDGDD allow for the assessment of mitigating and aggravating circumstances not only in relation to the facts constituting the infringement, but also in relation to the past or present conduct of the responsible entity, including any relevant considerations that may be obtained from previous sanctioning proceedings conducted by this supervisory authority resulting in a fine. In other words, it allows for the evaluation of the controller's monitoring record where applicable, or, equivalently, their behavioral profile or general attitude with regard to GDPR compliance, and the consideration of any relevant prior infringements (Recital 148 of the GDPR) or their response to prior breaches in order to prevent infringements of the same level and characteristics and ensure compliance with the GDPR in general. Recital 148 of the GDPR states, “In order to strengthen the application of the rules of this Regulation [...]” and indicates in this regard that “Special attention should, however, be paid to the nature, seriousness and duration of the infringement, its intentional character [...] or any relevant breaches [...]”. The weight to be given to these grading criteria will depend on the specific circumstances of the case in question. Obviously, when the infringing entity persists in the infringement, worsening its behavior under the aforementioned conditions, the amount of the penalty to be imposed may be much higher, especially considering the level of severity attributed to the type of infringement committed. Therefore, in accordance with section (e) of Article 83.2 of the GDPR, in determining the amount of the administrative fine, all prior infringements by the controller or processor must be taken into account in order to assess the unlawfulness of the conduct analyzed or the culpability of the offending party. Furthermore, a correct interpretation of the provision of Article 83.2(e) of the GDPR cannot disregard the purpose of the rule: to decide the amount of the administrative fine in the individual case, always ensuring that the penalty is proportionate, effective, and dissuasive. There are numerous sanctioning procedures processed by the Spanish Data Protection Agency (AEPD) in which TME has been sanctioned for GDPR infringements for acts committed prior to those that are the subject of these proceedings. The following cases can be cited, in which TME did not act correctly when identifying the person requesting its services, resulting in C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 44/46 identity theft (issuance of a duplicate SIM card): 1. EXP202206971: Resolution of 09/03/2023 imposing a fine of 70,000 euros, for acts committed on 27/05/2022. 2. EXP202211479: Resolution of 13/06/2023 imposing a fine of €70,000 for acts committed on 24/08/2022. 3. EXP202209359: Resolution of 16/06/2023 imposing a fine of €70,000 for acts committed in May 2022. 4. EXP202207989: Resolution of 13/11/2023 imposing a fine of €70,000 for acts committed on 29/07/2020. Given the repeated resolutions based on acts similar to those that are the subject of the proceedings, it is understood that the aggravating circumstance provided for in Article 83.2(e) of the GDPR applies. Article 83.2.k of the GDPR in conjunction with Article 76.2(b) of the LOPDGDD: “The connection between the infringer's activity and the processing of personal data.” The activity of the allegedly infringing entity is linked to the processing of personal data of both clients and third parties. The processing of personal data is essential to the activity carried out by the defendant, making the significance of the conduct that is the subject of this complaint undeniable. Furthermore, the data processing for which the sanction is imposed is carried out in the course of the defendant's main activity. This circumstance, in general, constitutes an aggravating factor. This has also been the view of the National Court in its Judgment of September 13, 2024, which states: “In the case at hand, the appellant achieved a turnover exceeding 46 million euros in 2018 and has more than 600 employees. Therefore, the imposed sanction cannot be considered disproportionate given the circumstances, taking into account its turnover and its connection to the processing of personal data, considering the number of employees and its activities.” Based on the foregoing, and considering the requirement that the fine be effective, proportionate, and dissuasive, and with the aim of ensuring effective compliance with the GDPR and the LOPDGDD, the assessment of the circumstances contemplated in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, considered together, with respect to the infringement of the provisions of Article 6 of the GDPR, allows for the imposition of an administrative fine of €200,000.00 (two hundred thousand euros). Therefore, in accordance with applicable legislation and having assessed the criteria for determining the severity of the penalty, once the infringement has been proven, the Presidency of the Spanish Data Protection Agency RESOLVES: C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 45/46 FIRST: TO IMPOSE on TELEFÓNICA MÓVILES ESPAÑA, S.A., with Tax Identification Number A78923125, for an infringement of Article 6.1 of the GDPR, classified under Article 83.5 of the GDPR, a fine of two hundred thousand euros (€200,000). SECOND: TO NOTIFY TELEFÓNICA MÓVILES ESPAÑA, S.A. of this resolution. THIRD: This resolution will become enforceable once the deadline for filing the optional appeal for reconsideration (one month from the day following notification of this resolution) has expired without the interested party having exercised this right. The sanctioned party is advised that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with the provisions of Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in conjunction with Article 68 of the LPACAP. 62 of Law 58/2003, of December 17, by depositing the fine, indicating the Tax Identification Number (NIF) of the sanctioned party and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A. Otherwise, collection will be pursued during the enforcement period. Once the notification is received and becomes enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for making a voluntary payment will be the 20th of the following month or the next business day thereafter. If the date falls between the 16th and the last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day thereafter. In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be made public. Publication will take place once the interested parties have been notified. This resolution, which concludes the administrative process pursuant to Article 50 of the LOPDGDD, may be appealed. 48.6 of the LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the interested parties may, optionally, file an appeal for reconsideration with the Presidency of the Spanish Data Protection Agency within one month from the day following notification of this resolution, or directly file an contentious-administrative appeal with the Contentious-Administrative Chamber of the National Court, pursuant to the provisions of Article 25 and paragraph 5 of the fourth additional provision of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction, within two months from the day following notification of this act, as provided for in Article 46.1 of the said Law. Finally, it is noted that, in accordance with the provisions of Article 90.3 a) of the LPACAP, a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an appeal with the Administrative Court. If this is the case, the interested party must formally communicate this fact by means of a written submission addressed to the Spanish Data Protection Agency, presenting it through C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es 46/46 the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica- web/], or through one of the other registries provided for in Article 16.4 of Law 39/2015, of October 1. They must also provide the Agency with the documentation that proves the effective filing of the appeal with the Administrative Court. If the Agency does not receive notification of the filing of an administrative appeal within two months of the day following notification of this resolution, it will terminate the precautionary suspension. Lorenzo Cotino Hueso President of the Spanish Data Protection Agency C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeaepd.gob.es




