Vodafone Group—Germany's data protection authority fined Vodafone a record €45M over eSIM authentication flaws and partner fraud oversight failures
Germany's Federal Commissioner for Data Protection (BfDI) imposed a combined €45 million in fines on Vodafone Germany, its largest since GDPR took effect, after finding eSIM authentication vulnerabilities that exposed customer profiles to unauthorized access and inadequate oversight of retail partner agencies that enabled fraud. The BfDI noted Vodafone cooperated throughout the investigation, disclosed incriminating circumstances, and has since revised partner-vetting procedures and agreed to follow-up compliance checks.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Data Security | -against | primary | -1.00 |
| Overall incident score = | -0.993 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.66)
Evidence (2 signals)
Heise: BfDI record fines - Vodafone pays 45 million euros
Heise online reported on the record BfDI fine against Vodafone Germany over eSIM security vulnerabilities and partner fraud oversight failures, noting it was the largest GDPR fine issued by the German federal data protection authority to date.
BfDI official press release: fines against Vodafone totaling €45M for eSIM and partner oversight failures
Germany's Federal Commissioner for Data Protection and Freedom of Information (BfDI) announced administrative fines against Vodafone Germany totaling €45 million (comprising a €30M and a €15M fine per the EDPB record), the highest since GDPR took effect, citing eSIM authentication vulnerabilities and inadequate partner-agency oversight that enabled fraud.