Skip to main content

Vodafone GroupGermany's data protection authority fined Vodafone a record €45M over eSIM authentication flaws and partner fraud oversight failures

Germany's Federal Commissioner for Data Protection (BfDI) imposed a combined €45 million in fines on Vodafone Germany, its largest since GDPR took effect, after finding eSIM authentication vulnerabilities that exposed customer profiles to unauthorized access and inadequate oversight of retail partner agencies that enabled fraud. The BfDI noted Vodafone cooperated throughout the investigation, disclosed incriminating circumstances, and has since revised partner-vetting procedures and agreed to follow-up compliance checks.

Scoring Impact

TopicDirectionRelevanceContribution
Data Security-againstprimary-1.00
Overall incident score =-0.993

Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.66)

Evidence (2 signals)

Confirms Legal Action Jun 6, 2025 documented

Heise: BfDI record fines - Vodafone pays 45 million euros

Heise online reported on the record BfDI fine against Vodafone Germany over eSIM security vulnerabilities and partner fraud oversight failures, noting it was the largest GDPR fine issued by the German federal data protection authority to date.

Confirms Legal Action Jun 5, 2025 verified

BfDI official press release: fines against Vodafone totaling €45M for eSIM and partner oversight failures

Germany's Federal Commissioner for Data Protection and Freedom of Information (BfDI) announced administrative fines against Vodafone Germany totaling €45 million (comprising a €30M and a €15M fine per the EDPB record), the highest since GDPR took effect, citing eSIM authentication vulnerabilities and inadequate partner-agency oversight that enabled fraud.

Related: Same Topics