Get tomorrow's brief in your inbox
Sunday, March 16, 2026
Today: Spain's data protection authority fined Vodafone España €200,000 for issuing a duplicate SIM card without proper identity verification, enabling fraudulent bank account access under Article 6(1) GDPR. EFF and MuckRock released their 2026 Foilies awards highlighting government transparency failures, including Texas Gov. Greg Abbott withholding communications with Elon Musk and Vancouver implementing new public records access fees. Justice Amy Coney Barrett discussed the Supreme Court's approach to separate opinions at a Library of Congress event following the 160-page tariffs ruling that exposed divisions over the major questions doctrine.
Vodafone España Fined €200,000 for SIM-Swap Fraud (EXP202308705)
Spain's AEPD fined Vodafone España €200,000 for violating Article 6(1) GDPR after issuing a duplicate SIM card to an impersonator without adequate identity verification. On February 8, 2023, an unknown third party changed the email address on a LOWI customer account (a Vodafone brand) and requested a duplicate SIM card delivered to another address. Vodafone issued the card on February 9, 2023, after the requester passed the company's identity checks. The third party intercepted SMS authentication codes and executed unauthorized transactions on the data subject's bank accounts. The AEPD held that Vodafone processed personal data without a lawful basis because it failed to verify that the requester was the legitimate subscriber. The decision is notable for analyzing SIM-swap fraud primarily under Article 6(1) GDPR (lawfulness of processing) rather than Article 5(1)(f) (integrity and confidentiality) or Article 32 (security measures), which are more common frameworks for telecommunications breach cases.
Spain's €200,000 Fine Sets Precedent for SIM-Swap Authentication Standards
The Spanish DPA's €200,000 fine against Vodafone España establishes a clear standard that telecommunications providers bear responsibility for verifying customer identity before issuing duplicate SIM cards, even when fraudsters pass existing authentication procedures. The ruling treats inadequate identity verification as a failure to establish lawful processing under Article 6(1) GDPR, not merely a security lapse. This analysis shifts liability directly to the authentication mechanism itself. The case involved a February 2023 incident where a third party modified account credentials online, requested a duplicate SIM card, and used intercepted SMS codes to access the victim's bank accounts. The data subject filed a complaint on May 17, 2023. Vodafone's defense that the requester passed identity checks was rejected by the authority. For compliance teams, this decision means that telecommunications providers in EU jurisdictions must implement verification procedures sufficient to prevent impersonation, regardless of whether fraudsters defeat existing controls.
EFF and MuckRock Release 2026 Foilies Highlighting Government Transparency Failures
The Electronic Frontier Foundation and MuckRock released their 2026 Foilies awards recognizing agencies and officials that obstruct public records access during Sunshine Week (March 15-21). Texas Gov. Greg Abbott's office received the "Love Letters Award" for withholding 1,400 pages of communications with Elon Musk, with approximately 1,200 pages fully redacted despite a Texas Attorney General order to release the records. Abbott's office claimed the communications contained confidential legal discussions, economic development strategies, and "intimate and embarrassing" information exempt under Texas public records law. Vancouver, British Columbia received the "Surcharge, Eh? Award" for implementing a $10 Canadian fee ($7.33 USD) for each non-personal public records request, requiring residents to pay twice for records already funded by taxes. The Department of Homeland Security received the "Shady Screenshot Award," and DOGE received the "Discardment of Government Efficiency Award." EFF also highlighted positive examples, noting Northern Nevada Public Health provided restaurant health inspection records to journalism students within 20 minutes, while the FCC has provided no response to student FOIA requests filed seven months ago for consumer complaints about NPR and PBS stations.
Justice Barrett Discusses Supreme Court Separate Opinion Practice After 160-Page Tariffs Ruling
Justice Amy Coney Barrett discussed the Supreme Court's approach to separate opinions during a March 12 Library of Congress event, weeks after the court issued a 160-page tariffs ruling with multiple concurrences and dissents. The February 20 tariffs case included Chief Justice Roberts' majority opinion, Justice Kavanaugh's principal dissent, and five additional separate writings exposing divisions over the major questions doctrine. Barrett and Justice Gorsuch each wrote concurrences despite joining the majority in full. Justice Kagan wrote a separate opinion joined by Justices Sotomayor and Jackson. Justice Jackson wrote a solo opinion. Justice Thomas joined Kavanaugh's dissent but also wrote his own separate dissent. Barrett explained that she writes separately only to clarify positions that might otherwise appear inconsistent or to contribute to legal development, noting that Chief Justice Marshall convinced the court to abandon seriatim opinions (individual opinions from each justice) in favor of unified opinions of the court. During the 2024-25 term, the court issued 67 opinions of the court, 50 concurring opinions, and 48 dissenting opinions. Barrett stated she tries to let the majority opinion speak for the court except when explanation is necessary to avoid apparent inconsistency or when she has something to add to legal development.
Telecommunications providers: Audit SIM card duplication procedures immediately following Spain's €200,000 Vodafone fine. Implement multi-factor identity verification beyond account credentials. Consider requiring in-person ID verification, biometric checks, or time-delayed activation for remotely-requested duplicate SIM cards. Document all verification procedures and maintain audit logs under Article 30 GDPR processing records requirements.
Financial institutions: Evaluate SMS-based two-factor authentication systems in light of the Spanish SIM-swap case. SMS interception enabled fraudulent bank account access despite the victim maintaining control of their phone number on paper. Consider migrating to app-based authenticators (Google Authenticator, Authy) or hardware tokens (YubiKey) that are not vulnerable to SIM-swap attacks. Update security incident response plans to include procedures for customers reporting unauthorized SIM card changes.
Government contractors and regulated entities: Review communications with government officials to determine whether they are subject to public records laws. The Texas Attorney General ordered release of Abbott-Musk communications despite executive office exemption claims. Implement document retention policies that account for potential FOIA or state public records requests. Train employees to avoid creating records with language that could be embarrassing or damaging if disclosed.
Organizations subject to FOIA or state transparency laws: Audit response procedures following the 2026 Foilies highlighting seven-month FCC delays and fully-redacted Texas records releases. Verify compliance with statutory deadlines (typically 5-20 business days depending on jurisdiction). Document reasons for redactions and exemption claims. Implement tracking systems for incoming requests to prevent missed deadlines.
Privacy teams in EU-regulated organizations: Note the AEPD's Article 6(1) GDPR analysis in the Vodafone case. Spanish authorities treated inadequate identity verification as a failure to establish lawful processing, not merely a security deficiency under Article 32. This expands the compliance scope for identity verification procedures beyond security risk management into fundamental lawfulness determinations. Review authentication systems for any process that could enable unauthorized third-party access to personal data if identity checks fail.