EU Regulation 2016/679 - Decision Register

DECISION OF THE GERMAN BfDI / JUNE 2025

Vodafone €45 Million BfDI Fine, 2025 eSIM and Partner-Agency Decision

Germany's federal data protection commissioner issued two fine notices against Vodafone GmbH totalling €45 million: €15 million for failing to supervise the partner agencies processing on its behalf, and €30 million for authentication weaknesses that let unauthorised third parties retrieve other subscribers' eSIM profiles. Vodafone accepted both and paid in full. It is the largest GDPR fine any German authority has imposed.

Fine amount

€45,000,000

Issuing DPA

German BfDI

Announced

June 2025

Status

Accepted and paid

Articles cited

28(1), 32(1)

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DECISION SUMMARY

What happened

In June 2025 the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), Germany's federal data protection commissioner, announced two fine notices against Vodafone GmbH totalling €45 million. The two notices address different failures and were issued under different articles, but both trace back to the same root cause the commissioner identified: systems and processes that had not kept pace with the risk they carried.

The €15 million notice concerns Vodafone's partner agencies. Under Article 28(1) a controller may only use processors that provide sufficient guarantees of appropriate technical and organisational measures, and must satisfy itself that they do. The BfDI found Vodafone had not adequately reviewed and monitored the agencies acting on its behalf. Staff at those agencies booked fictitious contracts and contract changes to customers' detriment.

The €30 million notice concerns authentication. The procedure spanning the MeinVodafone online customer portal and the telephone hotline was weak enough that unauthorised third parties could obtain eSIM profiles belonging to other subscribers, a breach of the Article 32(1) obligation to implement security measures appropriate to the risk. The BfDI additionally issued a warning, rather than a further fine, over Article 32(1) weaknesses found in certain sales systems.

Why an eSIM profile matters

An eSIM profile is the credential that binds a phone number to a device. Anyone who can provision another person's eSIM onto hardware they control can receive that person's calls and text messages, which in practice means receiving their SMS one-time passcodes. That is the mechanism behind SIM-swap fraud, and it is why an authentication weakness at a mobile operator is not a contained telecoms problem: it is a route into the victim's banking, email and account-recovery flows at every unrelated service that still treats a phone number as a second factor. The support desk and the self-service portal are the two doors, and the BfDI found both inadequately locked.

Why the fine was this size

Both Article 28 and Article 32 sit in the lower of the GDPR's two fining tiers. Article 83(4) caps a lower-tier infringement at €10 million or 2% of total worldwide annual turnover, whichever is higher. The arithmetic is worth following, because it contradicts a common assumption. A €30 million notice cannot have been set against the €10 million fixed limb; the percentage limb must have been the operative ceiling. "Lower tier" describes which obligations were breached, not how much the breach can cost. For a large undertaking a processor-oversight or security failure is capable of costing more than a consent or transparency breach at a smaller company, even though consent sits in the upper tier.

The mitigating side is unusually well documented. The commissioner, Prof. Dr. Louisa Specht-Riemenschneider, said Vodafone had cooperated continuously and without restriction, and that the company had disclosed self-incriminating circumstances, which under Article 83(2)(f) and (h) is exactly the conduct the fining framework is meant to reward. Vodafone substantially improved its processes and systems, including replacing certain infrastructure, revised how it selects and audits partner agencies, and ended its relationships with the fraudulent partners.

Resolution and status

Vodafone accepted both notices and paid the full €45 million to the federal treasury. That is the most unusual feature of the case. German fines of this size are normally contested, and contesting them has normally worked: the BfDI's €9.55 million fine on 1&1 Telecom was cut to €900,000 by the Bonn Regional Court, Lower Saxony's €10,417,000 notebooksbilliger.de fine now stands at €900,000 after the Oberlandesgericht Celle ruled in December 2025, and Berlin's €14.5 million Deutsche Wohnen decision was vacated altogether. Against that record, €45 million paid without challenge is the largest sum a German authority has actually collected under the GDPR, not merely the largest it has demanded. The BfDI has said it will carry out follow-up reviews to test whether the remediation is effective.

What this decision tells controllers

Three things. First, identity-proofing at the support desk is now the most consistently fined Article 32 control in Europe: 1&1 in Germany, Free Mobile in France and Vodafone all turn on someone persuading a human or a portal that they were the customer. If a caller can obtain or move a credential by supplying details that are widely known or easily guessed, the control is inadequate regardless of what the policy says.

Second, Article 28 is enforceable on its own. The fictitious-contract fraud was committed by agency staff, not by Vodafone, and the €15 million notice still landed on Vodafone, because the duty to select and supervise processors is the controller's and does not transfer with the work. A signed data processing agreement is the start of that duty, not the discharge of it.

Third, the commissioner made the framing explicit and general: organisations across industries are carrying IT modernisation backlogs, and those backlogs become security compromises. Her summary of the case was that companies should be investing rather than incurring risks. Deferred replacement of authentication infrastructure is not a neutral cost saving; it is an accruing, and now priced, regulatory liability.

FREQUENTLY ASKED

About the Vodafone €45 million BfDI fine

Why was Vodafone fined €45 million?
Germany's Federal Commissioner for Data Protection and Freedom of Information (BfDI) issued two separate fine notices against Vodafone GmbH. The first, €15 million, was for inadequately selecting, reviewing and monitoring the partner agencies acting as processors on Vodafone's behalf, an Article 28(1) failure: staff at those agencies booked fictitious contracts and contract changes to customers' detriment. The second, €30 million, was for weaknesses in the authentication procedure spanning the MeinVodafone online portal and the telephone hotline, an Article 32(1) failure that allowed unauthorised third parties to obtain eSIM profiles belonging to other subscribers. The BfDI additionally issued a warning over Article 32(1) weaknesses found in certain sales systems.
Is this the largest GDPR fine in Germany?
Yes. At €45 million across the two notices it exceeds the previous German record, the €35,258,707.95 fine the Hamburg commissioner imposed on H&M Hennes & Mauritz Online Shop A.B. & Co. KG in October 2020 for monitoring warehouse employees. It is not among the largest GDPR fines in Europe: Meta's €1.2 billion transfer fine, Uber's €825 million Article 22 fine and Amazon's €746 million CNPD fine (since annulled) are all an order of magnitude larger. Germany's federated structure, with enforcement split across the BfDI and 16 Land authorities, has historically produced smaller headline figures than the single-DPA member states that host Big Tech's European establishments.
Why did the BfDI handle this rather than a state DPA?
Germany has 17 data protection authorities: the federal BfDI plus one for each of the 16 Länder. The Land authorities supervise the private sector within their territory, but the BfDI has direct jurisdiction over federal public bodies, federal agencies, postal services and telecommunications providers. Vodafone GmbH is a telecoms provider, so it falls within the federal commissioner's remit. That is why the German record sits with the BfDI rather than with a Land DPA, even though Land authorities handle the great majority of German private-sector enforcement.
Is the Vodafone fine final, or under appeal?
Final. Unlike most large German fines, this one was not contested. The BfDI's announcement states that the fines were accepted and have already been paid in full to the federal treasury. That distinguishes it sharply from the German cases that are usually cited: the 1&1 Telecom fine was cut from €9.55 million to €900,000 by the Bonn Regional Court, notebooksbilliger.de's €10,417,000 was cut to a standing €900,000 by the Oberlandesgericht Celle in December 2025, and the Berlin Deutsche Wohnen decision was vacated outright. Vodafone's €45 million stands as imposed.
How can a lower-tier infringement produce a €45 million fine?
Articles 28 and 32 both sit in the Article 83(4) lower tier, capped at €10 million or 2% of total worldwide annual turnover, whichever is higher. The €30 million notice therefore cannot have been set against the €10 million fixed limb: the percentage limb must have been the operative ceiling. This is a useful corrective to the common assumption that the lower tier means small fines. For a large undertaking the 2% limb is the real cap, and a processor-oversight or security failure can cost more than a headline consent breach at a smaller company.
What did the BfDI say about Vodafone's cooperation?
The Federal Commissioner, Prof. Dr. Louisa Specht-Riemenschneider, said Vodafone had cooperated continuously and without restriction, and noted that the company had disclosed self-incriminating circumstances. The BfDI's announcement records that Vodafone substantially improved its processes and systems, including replacing certain infrastructure, revised how it selects and audits partner agencies, and terminated relationships with the fraudulent partners. The commissioner framed the case as a warning about IT modernisation backlogs across industries, summarising it as investing rather than incurring risks. The BfDI said it would carry out follow-up reviews to assess whether the measures are effective.

CROSS-REFERENCES

Related entries on this register

SUPERVISORY AUTHORITY

German BfDI + State DPAs

How Germany's federated enforcement works across the BfDI and 16 Land authorities, and where this record fine sits among German decisions.

Open reference →

ARTICLE 32

Article 32 Security Fines

The security-of-processing obligation, and the authentication cases (1&1, Free Mobile, Vodafone) that keep defining it.

Open reference →

ARTICLE 83

Administrative Fines Explained

Why a lower-tier infringement can still produce a €30 million notice: the 2% turnover limb, not the €10 million fixed limb.

Open reference →

ARTICLE 5

Article 5 Enforcement

H&M and notebooksbilliger, the German employment-monitoring cases this decision overtook.

Open reference →

SECTOR

GDPR Fines by Industry

Telecommunications enforcement patterns across Germany, Italy, Spain and Greece.

Open reference →

REGISTER

Full Decision Register

Every major GDPR fine indexed by company, country, year and violation type.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of September 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28