Vodafone gets GDPR fine in Spain for oversight failures after ransomware breach
( September 17, 2026, 16:59 GMT | Official Statement) -- MLex Summary: Telecoms operator Vodafone España was fined €400,000 by Spain’s data protection authority after a cyberattack attack on its incident-management service provider. The incident exposed unencrypted phone numbers of 486,768 customers. The authority said that Vodafone failed to adequately supervise the provider or ensure timely patching of a known critical vulnerability, breaching Article 32 of the GDPR.The decision is attached in Spanish. ...
Prepare for tomorrow’s regulatory change, today
MLex identifies risk to business wherever it emerges, with specialist reporters across the globe providing exclusive news and deep-dive analysis on the proposals, probes, enforcement actions and rulings that matter to your organization and clients, now and in the longer term.
Know what others in the room don’t, with features including:
- Daily newsletters for Antitrust, M&A, Trade, Data Privacy & Security, Technology, AI and more
- Custom alerts on specific filters including geographies, industries, topics and companies to suit your practice needs
- Predictive analysis from expert journalists across North America, the UK and Europe, Latin America and Asia-Pacific
- Curated case files bringing together news, analysis and source documents in a single timeline
Experience MLex today with a 14-day free trial.