Garante per la protezione dei dati personali (Italy) - 351/2026
Italy's Garante fined a marketing company €1,500 for unlawful unsolicited communications.
Summary
Italy's Garante per la protezione dei dati personali has fined an individual company, Ditta individuale Francesco Gagliardi, €1,500 for unlawfully sending unsolicited marketing communications. The company purchased a dataset of approximately 2,500 professional contacts from Apollo.io and used it for a B2B marketing campaign, relying on legitimate interest as the legal basis. The Garante found violations of GDPR Articles 5(1)(a) and 14, and Article 130 of Italy's d.lgs. 196/2003 (implementing the ePrivacy Directive), stating that consent, not legitimate interest, was required for such marketing.
Full text
Help Garante per la protezione dei dati personali (Italy) - 351/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:42, 28 August 2026 view source Carloc (talk | contribs)728 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 14:42, 28 August 2026 Garante per la protezione dei dati personali - 351/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 14 GDPR Article 5(2) GDPR Article 13 ePrivacy DirectiveArticle 130 d.lgs. 196/2003 Type: Complaint Outcome: Upheld Started: 05.03.2025 Decided: 14.05.2026 Published: Fine: 1500.0 EUR Parties: Ditta individuale Francesco Gagliardi National Case Number/Name: 351/2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: carloc The DPA fined a marketing company €1,500 for unlawfully sending unsolicited communications in the context of a B2B marketing campaign. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts An individual company (the controller) engaged in a B2B marketing campaign. To this end, it bought a data set from a third-party: a sales platform called Apollo.io. The set consisted of about 2,500 professional contacts, including email addresses, phone numbers, and personal details of the contacts as well as their role within organizations. It is not known how Apollo acquired the information. The controller then used the data for sending unsolicited marketing communications. The controller relied on its legitimate interest as the legal basis of its legitimate interest. Every email contained a short footer that explained the legal basis of the processing, identified Apollo.io as the source for the email address, and included an opt-out link. An individual (the data subject) filed a complaint after receiving one of said emails. Holding Overall, the DPA found violations of Articles 5(1)(a) and 14 GDPR as well as Art. 130 c.1. d. lgs. 196/2003 (i.e.: the Italian implementation of Article 13 of the ePrivacy Directive). The DPA issued a E1,500 fine. In quantifying the fine, the DPA took into account that the controller had taken steps to fix its violations before the decision. Additionally, the DPA ordered the controller to bring its processing of personal data into compliance – which included, among others, erasing the data and providing the addressees of its marketing campaign with all the information required by Article 14. On the applicable legal regime First, the DPA clarified that the case fell within the scope of both the GDPR and the Article 13 of the ePrivacy Directive (as well as its implementation in Italian law). The DPA pointed out that the data set, which the controller bought and processed, contained at least some personal data. On these grounds, the DPA held that the case fell within the scope of the GDPR even though the controller’s campaign was B2B in nature. With regards to the ePrivacy Directive, the DPA observed that Article 13 covers marketing carried out towards subscribers or users!!! of an electronic communications network, and clarified that the notions of “subscriber” or “users” may also cover legal persons. On these grounds, the DPA held that the Article applied to the case at hand regardless of the personal or non-personal nature of the data processed. Lawfulness Article 13 of the ePrivacy Directive requires consent for sending unsolicited marketing emails. In the DPA’s view, this made it unlawful for the controller to rely on legitimate interest as its legal basis. On these grounds, the DPA held that the controller unlawfully processed personal data for marketing purposes. Transparency The DPA acknowledged that the controller’s marketing emails contained a privacy notice but found it to be severely lacking. On these grounds, the DPA held that the controller violated Article 14 GDPR as well as the transparency principle. On the controller’s accountability In its defence, the controller pointed out that Apollo had put forward claims that its processing complied with applicable laws and that the data set it sold, could lawfully be used for marketing. The DPA, however, applied the principle of accountability (Article 5(2) GDPR) and concluded that the documental or contractual guarantees provided a third-party, did not exempt the controller from assessing the lawfulness of its processing and did not shield the controller from liability. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details. [Web Doc. No. 10263918] Decision of May 14, 2026 Register of Decisions No. 351 of May 14, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, President; Prof. Ginevra Cerrina Feroni, Vice President; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “Regulation” or “GDPR”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003), as amended by Legislative Decree No. 101 of August 10, 2018, containing provisions for the adaptation of national law to the aforementioned Regulation (hereinafter the “Code”); HAVING REGARD TO the documentation on file; HAVING REGARD TO the observations made by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No. 1/2000, adopted by resolution of June 28, 2000; REPORTER: Prof. Pasquale Stanzione; 1. THE PRELIMINARY INVESTIGATION CONDUCTED 1.1. Introduction By communication ref. no. 177444 dated December 22, 2025 (served on the same date via certified email), which is hereby deemed to be incorporated in its entirety, the Office initiated, pursuant to Article 166, paragraph 5, of the Code, a proceeding to adopt the measures referred to in Art 58, para 2, of the Regulation against the sole proprietorship of Francesco Gagliardi (hereinafter also referred to as the “Business” or the “Owner”). The proceedings stem from a report dated May 5, 2025 (registered under ref. no. 60002 on May 6, 2025), in which the complainant informed the Authority that he had received a promotional email from the Firm, which had obtained his email address through the Apollo.io platform (hereinafter also “Apollo”). This information was disclosed to the complainant by the Company, and the complainant thus learned that, although he had never registered with or given consent to the collection or processing of his personal data by the Apollo platform, nor had he received any privacy notice from it, his personal email address and other information pertaining to him were nonetheless available on the platform. The complainant therefore exercised his right to erasure of his data, a request that was subsequently granted by the Company. 1.2. The Authority’s Request for Information On September 18, 2025 (Ref. No. 122622 of the same date), the Office issued a request for information to the Company, pursuant to Article 157 of the Code, regarding the matters raised in the complaint, also requesting that the Company explain the measures taken to ensure that marketing activities are conducted in compliance with applicable law and, in particular, with specific reference to the use of the Apollo platform, to provide information regarding: the origin of the personal data; the grounds justifying its collection and subsequent processing; whether and
Indicators of Compromise
- domain — apollo.io