Vodafone Romania Faces Penalties under GDPR For Customer Data Leaks Through WhatsApp and Improper Email Practices

Vodafone Romania was fined EUR 15,000 for GDPR violations, including unauthorised data sharing via WhatsApp and email. The investigation revealed failures in implementing proper safeguards to prevent employee and third-party access to sensitive customer information.

Vodafone Romania Faces Penalties under GDPR For Customer Data Leaks Through Whatsapp And Improper Email Practices

Vodafone Romania Penalised for GDPR Breach in Telecom Services

The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) has imposed a fine of RON 74,526 (EUR 15,000) on Vodafone Romania for breaches of Articles 32(4) and 32(1)(b) of the General Data Protection Regulation (GDPR).

The ruling, issued on 20 January 2025, highlighted failures in safeguarding customer data, including personal details such as names, personal identification numbers, and addresses.

ANSPDCP’s investigation revealed troubling practices that exposed sensitive customer data. Among the key issues were the sharing of invoice photos containing personal data with unauthorised third parties, failure to use blind carbon copy (BCC) when sending emails, and sharing screenshots of application interfaces via WhatsApp.

These actions led to the unauthorised processing of personal data by employees and third parties.

Vodafone’s failure to implement proper technical and organisational measures raised red flags with regulators, ultimately resulting in this penalty.

Comunicat_Presa_20_01_2025

Unpacking Vodafone’s GDPR Breaches

ANSPDCP’s investigation uncovered a series of missteps by Vodafone Romania that directly violated GDPR provisions.

Article 32 requires organisations to ensure the security of personal data through appropriate technical and organisational safeguards. Vodafone’s shortcomings, particularly in the telecommunications sector where data protection is paramount, were particularly concerning.

One key issue was the sharing of invoice photos containing sensitive customer data with third parties. This unauthorised disclosure not only breached confidentiality but also highlighted vulnerabilities in Vodafone’s data-sharing protocols. Such lapses are unacceptable in industries where consumer trust relies heavily on secure handling of personal information.

Additionally, the investigation found that Vodafone employees used email communication without applying BCC, resulting in personal data being inadvertently exposed to unintended recipients.

This practice, although seemingly minor, can have major privacy implications. The use of screenshots from internal application interfaces, shared through WhatsApp, further exemplified the company’s lack of strict controls over data processing.

Accountability and the Need for Stronger Safeguards

The fine imposed on Vodafone Romania sends a strong signal about the consequences of failing to protect customer data. At the heart of the matter lies Article 32(4) of the GDPR, which specifically mandates that entities using data processors must ensure these processors comply with security measures.

Vodafone’s apparent inability to enforce this requirement exposed systemic gaps in their data protection framework.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Technology Law.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.