In a press release earlier this month, the German data protection regulator confirmed that it had issued two fines totalling €45million against Vodafone GmbH.
The first fine of €15 million related to failings in the oversight of partner agencies. The regulator found that Vodafone had failed to properly supervise and audit third party processors which had resulted in the creation of fraudulent contracts and changes to contracts at the expense of customers.
The second fine of €30 million related to security failings which resulted in unauthorised access to the online platform and eSims.
The press release can be found here.
If you would like assistance with reviewing your relationships with third party processors to ensure you are complying with your obligations under GDPR, please email hello@hellodpo.com for more information about how we can help.