Garante per la protezione dei dati personali (Italy) - 10266250
Italian DPA fines a processor €15,300 for violating GDPR through unsolicited calls and ignoring data subject rights.
Summary
The Italian DPA has imposed a €15,300 fine on a data processor for multiple GDPR violations. The processor engaged in unsolicited promotional calls and emails to a data subject, despite their number being on an opt-out registry. Furthermore, the processor failed to properly handle the data subject's requests to exercise their rights and demonstrated a lack of understanding regarding processor duties and legal bases for data processing.
Full text
Help Garante per la protezione dei dati personali (Italy) - 10266250: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 16:09, 14 August 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators2 edits Tag: Decisions [1.0] (No difference) Latest revision as of 16:09, 14 August 2026 Garante per la protezione dei dati personali - 10266250 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 7 GDPR Article 12 GDPR Article 13 GDPR Article 14 GDPR Article 15 GDPR Article 22 GDPR Article 28 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 15300.0 EUR Parties: n/a National Case Number/Name: 10266250 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: sf The DPA imposed a €15,300.00 administrative fine on a processor after a promotional contact by the company revealed a lack of appropriate legal basis, non-compliance with their processor duties, and a restriction of data subject rights, violating Articles 5-7, 12-15, 22 and 28 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone number being registered with the Public-Opt-Out Registry. The processor failed to respond to the data subjects request to exercise his rights. The data subject had also sought compensation from the processor. The Processor dismissed the request with regard to its content and origin due to being subject to repeated fraudulent emails which aimed at soliciting undue payments. On 13 October 2025 the data subject submitted a complaint with the Italian DPA. In the course of the procedure by the DPA, the Processor first denied responsibility for the promotional contact made to the data subject, the DPA found that the caller ID number was not registered in the Register of Communications and Postal Operators (‘ROC’). After further questions by the DPA, the Processor claimed that the phone call was a mere clerical error made by an agent of the sub-processor (Vanille Service S.r.l.s.) it had engaged in the entry of the phone number. The Processor claimed to process data on behalf of Sorgenia (the controller). The Controller emphasised that the Processor was never authorised to use telemarketing to conduct sales, violating their contractual agreement. The Controller denied having any contractual relationship with the sub-processor as they never authorised the use of a sub-processor pursuant to Article 28 GDPR. Holding The DPA identified a contradictory classification of the controller and the processor, and thus subsequent obligations. The contract presented by the Processor declared the parties as independent controllers. Nonetheless, in 2018, the Processor accepted to be a processor under Article 28 GDPR. According to the DPA, the contractual relationship was not properly understood by the Processor, and correspondingly the GDPR obligations which follow. Firstly, the DPA held that in absence of demonstrating an appropriate legal basis, the promotional contact made by the Processor violated Articles 5, 6 and 7 GDPR. Furthermore, the DPA held that the failure by the Processor to adopt adequate measures to handle data subject requests concerning the exercise of their rights, and the inadequate response to the request submitted by the data subject, violated Articles 12, 13, 14, 15 and 22 GDPR. Lastly, the DPA found the Processor to be in violation of its processor duties in light of its appointment in 2018 under Article 28 GDPR, as it did not diligently assess the arrangement with the Controller, and lacked the prior written authorisation for engaging a sub-processor. The DPA imposed an administrative fine of €15,300.00 on the Processor, and ordered it to adopt appropriate measures to ensure that any further engagement of sub-processors complies with the GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10281706] Decision of June 18, 2026 Register of Decisions No. 472 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter the “Regulation”); HAVING REGARD TO Legislative Decree No. 196 of June 30, 2003 (Code on Data Protection, hereinafter the “Code”), as amended by Legislative Decree No. 101 of August 10, 2018, containing “Provisions for the alignment of national legislation with the provisions of Regulation (EU) 2016/679”; HAVING EXAMINED the documentation on file; HAVING CONSIDERED the observations made by the Secretary General pursuant to Article 15 of the Data Protection Authority’s Regulation No. 1/2000; RAPPORTEUR: Dr. Agostino Ghiglia; PREAMBLE 1. The complaints brought to the Authority’s attention. This Authority has received several complaints alleging that energy supply contracts were activated in the names of deceased individuals during periods following their deaths, as well as the occurrence, with respect to the aforementioned supply arrangements, of multiple switches to different energy companies operating in the free market. In addition, a complaint was received, submitted by Mr. XX, regarding the inadequate response provided by Acquirente Unico S.p.A., to the request to exercise rights submitted by the data subject on July 21, 2025, regarding the failure to update his personal data, which had been erroneously associated with a PDR not attributable to the complainant. 2. The Preliminary Investigation. The preliminary investigation was initially launched in response to the complaint filed by XX regarding the unlawful processing of the personal data of XX, who died on March 19, 2018. Specifically, the complaint alleged that Servizio Elettrico Nazionale S.p.A. had activated an electricity service in the name of the deceased, covering consumption for the years 2023 and 2024. In this regard, a request for information was therefore sent to the aforementioned company (see note dated July 11, 2024, ref. no. 85584/24), to which the company responded with a note dated September 30, 2024. In light of the statements made by Servizio Elettrico Nazionale S.p.A., a request for information was also sent to Acquirente Unico S.p.A. (hereinafter also “AU”), as the operator of the Integrated Information System (SII) (see letter dated November 5, 2024; ref. no. 129941/24; see the response from Acquirente Unico S.p.A. dated December 4, 2024), and, subsequently, to Acea Energia S.p.A. in its capacity as a dispatch user; Recital 1: Given that the latter had initially arranged to activate an energy supply on the open market at the POD assigned to XX (see note dated March 24, 2025; ref. no. 38941/25; see Acea Energia S.p.A.’s response dated April 22, 2025). On July 1, 2025, an inspection was also ordered against Acquirente Unico S.p.A. Subsequently, additional information was obtained through supplementary documentation submitted by the latter on July 1, 2025, thereby resolving the reservations raised during the inspection. Following the aforementioned on-site inspection and based on the findings thereof, it became necessary to initiate, ex officio, pursuant to Art. 21 of the Data Protection Authority’s Regulation No. 1/2019, to initiate a preli