{"id":17275,"date":"2024-12-11T06:00:15","date_gmt":"2024-12-11T06:00:15","guid":{"rendered":"https:\/\/letslaw.es\/?p=17275"},"modified":"2024-12-11T06:00:15","modified_gmt":"2024-12-11T06:00:15","slug":"the-phone-house-fine-spanish-aepd","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/the-phone-house-fine-spanish-aepd\/","title":{"rendered":"The Phone House and the Data Protection Agency face off in court over a 6.5\u20ac million fine"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">This past November, <\/span><b>one of the largest fines imposed by the Spanish Data Protection Agency<\/b><span style=\"font-weight: 400;\"> (AEPD) was debated in the National Court: a \u20ac6.5 million fine against the mobile phone, tariff, and technology store The Phone House for the hacking incident it suffered in April 2021.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">The Phone House Data Hack<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">As mentioned earlier, in April 2021, The Phone House experienced the <\/span><b>leak and hijacking of approximately 100 GB of personal data from up to three million<\/b><span style=\"font-weight: 400;\"> (3,000,000) customers, former customers, employees, and suppliers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The stolen information included personal data such as full names, ID numbers, addresses, emails, phone numbers, nationalities, birth dates, banking details, and even information about devices and products, such as insurance and IMEI codes for mobile phones.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Phone House fell victim to a ransomware attack by a well-known hacker group that typically steals company information and demands a &#8220;ransom&#8221; in exchange for not publishing the acquired data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this case, the cybercriminals demanded an undisclosed ransom to prevent the release of confidential information on the deep web. When the company refused to yield to the extortion, <\/span><b>the attackers made the stolen information public, putting millions of people at risk of fraud and identity theft<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Infringement and Penalty from the Spanish Data Protection Agency (AEPD)<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">According to the resolution issued by the National Court, dated September of this year, the Data Protection Agency issued a <\/span><b>sanctioning resolution on December 27, 2023, imposing a 6.5\u20ac million fine<\/b><span style=\"font-weight: 400;\"> due to a series of infringements.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Specifically, this fine is broken down into two violations:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A violation of Article 5.1.f) of the GDPR, classified under Article 83.5 of the GDPR, resulting in an administrative fine of 4,000,000\u20ac.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A violation of Article 32 of the GDPR, classified under Article 83.5 of the GDPR, resulting in an administrative fine of 2,500,000\u20ac.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Article 5.1.f) of the GDPR states that &#8220;personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (\u2018integrity and confidentiality\u2019).&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this case, while it is true that security breaches cannot always be anticipated, the AEPD maintains that: \u201cIt does not have a policy of dismissal in cases of cyberattacks, of any kind, nor for those affected by ransomware. Therefore, regarding data protection, the technical and organizational security measures to be implemented by data controllers and other obligations to be fulfilled under the GDPR must be adequate to the specific risks posed by the particular processing carried out by each controller.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The AEPD concluded that The Phone House did not have the appropriate technical or organizational measures in place.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On the other hand, Article 32 of the GDPR addresses the security of processing, which requires that, considering the state of the art, application costs, the nature, scope, context, and purposes of the processing, as well as the risks of varying probability and severity for the rights and freedoms of individuals, The Phone House, as the data controller, should have implemented appropriate <\/span><b>technical and organizational measures to ensure a level of security corresponding to the risk<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this regard, the AEPD highlighted \u201cthe inadequacy of the encryption algorithm, which is a true deficiency, an insecure algorithm that had been pointed out years earlier by the CCN, although it was only recommended in the aforementioned report. What the report shows is that TPHS was using this algorithm, and it is known to be defective. It should not be forgotten that the attacker obtained the credentials of several TPHS users.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For all these reasons, the AEPD determined that The Phone House did not adequately meet the security requirements for processing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The company, The Phone House Spain, which is controlled by the publicly listed group Global Dominion Access in Spain, filed a contentious-administrative appeal against the negative resolution due to administrative silence. In this appeal, it requested the precautionary suspension of the payment until the judges ruled on whether the measure could be annulled or, if applicable, confirmed. It argued that the &#8220;significant&#8221; amount claimed forced it to &#8220;cease meeting financial and business obligations.&#8221; Therefore, it will be necessary to wait for the National Court&#8217;s ruling to determine how this matter will be resolved.<\/span><\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/17275#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>This past November, one of the largest fines imposed by the Spanish Data Protection Agency (AEPD) was debated in the National Court.<\/p>\n","protected":false},"author":60,"featured_media":17271,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-17275","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=17275"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17275\/revisions"}],"predecessor-version":[{"id":17279,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17275\/revisions\/17279"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/17271"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=17275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=17275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=17275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}