A security flaw in Telefnica’s Movistar website exposed billing invoices for millions of customers. The flaw allowed someone viewing an account invoice to view someone else’s bill. Names, addresses, email addresses, fixed and mobile numbers and call records were exposed, a consumer group says. The incident comes two months after the European Union’s General Data Protection Regulation went into effect. Those found in breach of GDRP’s rules could face fines up of up to 4 percent of their annual revenue or 20 million.”]