ao link
Affino
Search Teiss
My Account
Remember Login
My Account
Remember Login

Dutch regulator fines Odido €1.5 million for inadequate wiretapping system security

The Dutch Authority for Digital Infrastructure (RDI) has fined telecommunications provider Odido €1,518,750 after finding that its wiretapping system failed to meet several legal security requirements. The regulator said the deficiencies, which included poor access controls and missing security documentation, posed risks of unauthorized access to sensitive information but have since been resolved.


According to the RDI, the investigation into Odido’s wiretapping system was conducted in 2021 and 2022. The probe revealed multiple shortcomings, including the absence of a legally required security plan. Such a plan outlines the technical and organizational measures needed to safeguard a wiretapping system and ensure compliance with national security standards.


The RDI also found that Odido had not properly screened employees with access to the system. Investigators reported that many staff members lacked clear job descriptions, signed confidentiality agreements, or Certificates of Good Conduct. In some cases, individuals not responsible for processing wiretapping data could still access it.


In addition, the digital security of the system’s access points was found to be inadequate. External suppliers had access to the wiretapping system, raising the possibility of exposure to classified state information and criminal investigation data.


A wiretapping system stores communications intercepted under legal authority, including phone calls, emails, and text messages. Because these systems handle highly sensitive information such as state secrets and evidence from criminal investigations, Dutch law mandates strict technical and procedural safeguards.


Following the investigation, Odido reportedly upgraded its wiretapping infrastructure to close the identified vulnerabilities. The RDI confirmed that the risks of unauthorized access have now been eliminated.


The regulator has taken similar enforcement actions in the past. Last year, telecommunications company Vodafone was fined €2.25 million for failing to comply with several legal requirements governing the security of its own wiretapping system.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Affino

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543