TL;DR for the DPO
June 2025: BfDI fines Vodafone Germany for EUR 45M. 15M for Art. 28 GDPR (failure to control partner sales agents who defrauded customers with fictitious contracts), 30M for Art. 32 (weaknesses in MeinVodafone portal authentication allowing unauthorized eSIM access). Lesson: the controller cannot delegate responsibility to the processor. Continuous control, not just contractual, is required.
The facts
Vodafone GmbH uses a network of partner agencies that sell phone contracts under Vodafone's brand. Despite being legally separate entities, they operate under Vodafone's brand, use hardware and software provided by Vodafone, and are bound to Vodafone's instructions via Data Processing Agreements. They therefore qualify as processors under Art. 28 GDPR.
Key principle: accountability is not delegable
BfDI explicitly stated that outsourcing processing activities does not outsource GDPR responsibility. The controller remains responsible for the conduct of its processors and must demonstrate it with documentary evidence: periodic audits, inspections, security reports received from the processor, records of non-conformities and corrective actions.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free