← Carolina Clear Tech

Legal & Privacy Brief

2026-03-16

Listen to this brief (10:15)

Download MP3
Show Notes

Show Notes - 2026-03-16

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief

Sunday, March 16, 2026

Today: Spain's data protection authority fined Vodafone España €200,000 for issuing a duplicate SIM card without proper identity verification, enabling fraudulent bank account access under Article 6(1) GDPR. EFF and MuckRock released their 2026 Foilies awards highlighting government transparency failures, including Texas Gov. Greg Abbott withholding communications with Elon Musk and Vancouver implementing new public records access fees. Justice Amy Coney Barrett discussed the Supreme Court's approach to separate opinions at a Library of Congress event following the 160-page tariffs ruling that exposed divisions over the major questions doctrine.

Enforcement Actions

Vodafone España Fined €200,000 for SIM-Swap Fraud (EXP202308705)

Spain's AEPD fined Vodafone España €200,000 for violating Article 6(1) GDPR after issuing a duplicate SIM card to an impersonator without adequate identity verification. On February 8, 2023, an unknown third party changed the email address on a LOWI customer account (a Vodafone brand) and requested a duplicate SIM card delivered to another address. Vodafone issued the card on February 9, 2023, after the requester passed the company's identity checks. The third party intercepted SMS authentication codes and executed unauthorized transactions on the data subject's bank accounts. The AEPD held that Vodafone processed personal data without a lawful basis because it failed to verify that the requester was the legitimate subscriber. The decision is notable for analyzing SIM-swap fraud primarily under Article 6(1) GDPR (lawfulness of processing) rather than Article 5(1)(f) (integrity and confidentiality) or Article 32 (security measures), which are more common frameworks for telecommunications breach cases.

Privacy Developments

Spain's €200,000 Fine Sets Precedent for SIM-Swap Authentication Standards

The Spanish DPA's €200,000 fine against Vodafone España establishes a clear standard that telecommunications providers bear responsibility for verifying customer identity before issuing duplicate SIM cards, even when fraudsters pass existing authentication procedures. The ruling treats inadequate identity verification as a failure to establish lawful processing under Article 6(1) GDPR, not merely a security lapse. This analysis shifts liability directly to the authentication mechanism itself. The case involved a February 2023 incident where a third party modified account credentials online, requested a duplicate SIM card, and used intercepted SMS codes to access the victim's bank accounts. The data subject filed a complaint on May 17, 2023. Vodafone's defense that the requester passed identity checks was rejected by the authority. For compliance teams, this decision means that telecommunications providers in EU jurisdictions must implement verification procedures sufficient to prevent impersonation, regardless of whether fraudsters defeat existing controls.

Policy Changes

EFF and MuckRock Release 2026 Foilies Highlighting Government Transparency Failures

The Electronic Frontier Foundation and MuckRock released their 2026 Foilies awards recognizing agencies and officials that obstruct public records access during Sunshine Week (March 15-21). Texas Gov. Greg Abbott's office received the "Love Letters Award" for withholding 1,400 pages of communications with Elon Musk, with approximately 1,200 pages fully redacted despite a Texas Attorney General order to release the records. Abbott's office claimed the communications contained confidential legal discussions, economic development strategies, and "intimate and embarrassing" information exempt under Texas public records law. Vancouver, British Columbia received the "Surcharge, Eh? Award" for implementing a $10 Canadian fee ($7.33 USD) for each non-personal public records request, requiring residents to pay twice for records already funded by taxes. The Department of Homeland Security received the "Shady Screenshot Award," and DOGE received the "Discardment of Government Efficiency Award." EFF also highlighted positive examples, noting Northern Nevada Public Health provided restaurant health inspection records to journalism students within 20 minutes, while the FCC has provided no response to student FOIA requests filed seven months ago for consumer complaints about NPR and PBS stations.

Justice Barrett Discusses Supreme Court Separate Opinion Practice After 160-Page Tariffs Ruling

Justice Amy Coney Barrett discussed the Supreme Court's approach to separate opinions during a March 12 Library of Congress event, weeks after the court issued a 160-page tariffs ruling with multiple concurrences and dissents. The February 20 tariffs case included Chief Justice Roberts' majority opinion, Justice Kavanaugh's principal dissent, and five additional separate writings exposing divisions over the major questions doctrine. Barrett and Justice Gorsuch each wrote concurrences despite joining the majority in full. Justice Kagan wrote a separate opinion joined by Justices Sotomayor and Jackson. Justice Jackson wrote a solo opinion. Justice Thomas joined Kavanaugh's dissent but also wrote his own separate dissent. Barrett explained that she writes separately only to clarify positions that might otherwise appear inconsistent or to contribute to legal development, noting that Chief Justice Marshall convinced the court to abandon seriatim opinions (individual opinions from each justice) in favor of unified opinions of the court. During the 2024-25 term, the court issued 67 opinions of the court, 50 concurring opinions, and 48 dissenting opinions. Barrett stated she tries to let the majority opinion speak for the court except when explanation is necessary to avoid apparent inconsistency or when she has something to add to legal development.

Compliance Takeaways