DECISION SUMMARY
What happened
In June 2025 the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), Germany's federal data protection commissioner, announced two fine notices against Vodafone GmbH totalling €45 million. The two notices address different failures and were issued under different articles, but both trace back to the same root cause the commissioner identified: systems and processes that had not kept pace with the risk they carried.
The €15 million notice concerns Vodafone's partner agencies. Under Article 28(1) a controller may only use processors that provide sufficient guarantees of appropriate technical and organisational measures, and must satisfy itself that they do. The BfDI found Vodafone had not adequately reviewed and monitored the agencies acting on its behalf. Staff at those agencies booked fictitious contracts and contract changes to customers' detriment.
The €30 million notice concerns authentication. The procedure spanning the MeinVodafone online customer portal and the telephone hotline was weak enough that unauthorised third parties could obtain eSIM profiles belonging to other subscribers, a breach of the Article 32(1) obligation to implement security measures appropriate to the risk. The BfDI additionally issued a warning, rather than a further fine, over Article 32(1) weaknesses found in certain sales systems.
Why an eSIM profile matters
An eSIM profile is the credential that binds a phone number to a device. Anyone who can provision another person's eSIM onto hardware they control can receive that person's calls and text messages, which in practice means receiving their SMS one-time passcodes. That is the mechanism behind SIM-swap fraud, and it is why an authentication weakness at a mobile operator is not a contained telecoms problem: it is a route into the victim's banking, email and account-recovery flows at every unrelated service that still treats a phone number as a second factor. The support desk and the self-service portal are the two doors, and the BfDI found both inadequately locked.
Why the fine was this size
Both Article 28 and Article 32 sit in the lower of the GDPR's two fining tiers. Article 83(4) caps a lower-tier infringement at €10 million or 2% of total worldwide annual turnover, whichever is higher. The arithmetic is worth following, because it contradicts a common assumption. A €30 million notice cannot have been set against the €10 million fixed limb; the percentage limb must have been the operative ceiling. "Lower tier" describes which obligations were breached, not how much the breach can cost. For a large undertaking a processor-oversight or security failure is capable of costing more than a consent or transparency breach at a smaller company, even though consent sits in the upper tier.
The mitigating side is unusually well documented. The commissioner, Prof. Dr. Louisa Specht-Riemenschneider, said Vodafone had cooperated continuously and without restriction, and that the company had disclosed self-incriminating circumstances, which under Article 83(2)(f) and (h) is exactly the conduct the fining framework is meant to reward. Vodafone substantially improved its processes and systems, including replacing certain infrastructure, revised how it selects and audits partner agencies, and ended its relationships with the fraudulent partners.
Resolution and status
Vodafone accepted both notices and paid the full €45 million to the federal treasury. That is the most unusual feature of the case. German fines of this size are normally contested, and contesting them has normally worked: the BfDI's €9.55 million fine on 1&1 Telecom was cut to €900,000 by the Bonn Regional Court, Lower Saxony's €10,417,000 notebooksbilliger.de fine now stands at €900,000 after the Oberlandesgericht Celle ruled in December 2025, and Berlin's €14.5 million Deutsche Wohnen decision was vacated altogether. Against that record, €45 million paid without challenge is the largest sum a German authority has actually collected under the GDPR, not merely the largest it has demanded. The BfDI has said it will carry out follow-up reviews to test whether the remediation is effective.
What this decision tells controllers
Three things. First, identity-proofing at the support desk is now the most consistently fined Article 32 control in Europe: 1&1 in Germany, Free Mobile in France and Vodafone all turn on someone persuading a human or a portal that they were the customer. If a caller can obtain or move a credential by supplying details that are widely known or easily guessed, the control is inadequate regardless of what the policy says.
Second, Article 28 is enforceable on its own. The fictitious-contract fraud was committed by agency staff, not by Vodafone, and the €15 million notice still landed on Vodafone, because the duty to select and supervise processors is the controller's and does not transfer with the work. A signed data processing agreement is the start of that duty, not the discharge of it.
Third, the commissioner made the framing explicit and general: organisations across industries are carrying IT modernisation backlogs, and those backlogs become security compromises. Her summary of the case was that companies should be investing rather than incurring risks. Deferred replacement of authentication infrastructure is not a neutral cost saving; it is an accruing, and now priced, regulatory liability.