[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnA45MLnHihiGq00DSCu5jisbtJgJhZb3Kw6C27OPuVI":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"2048ed1f-ca9d-441e-ad55-3a0e7ec342a8","Garante per la protezione dei dati personali (Italy) - 351\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-351-2026-dc0860","Comment: forgot about the comment ← Older revision Revision as of 14:58, 28 August 2026 (4 intermediate revisions by the same user not shown) Line 110: Line 110: An individual (the data subject) filed a complaint after receiving one of said emails. An individual (the data subject) filed a complaint after receiving one of said emails. === Holding === === Holding === Overall, the DPA found violations of Articles 5(1)(a) and 14 GDPR as well as Art. 130 c.1. d. lgs. 196\u002F2003 (i.e.: the Italian implementation of Article 13 of the ePrivacy Directive). Overall, the DPA found violations of Articles 5(1)(a) and 14 GDPR as well as Art. 130 c.1. d. lgs. 196\u002F2003 (i.e.: the Italian implementation of Article 13 of the ePrivacy Directive). The DPA issued a E1,500 fine. In quantifying the fine, the DPA took into account that the controller had taken steps to fix its violations before the decision. The DPA issued a €1,500 fine. In quantifying the fine, the DPA took into account that the controller had taken steps to fix its violations before the decision. Additionally, the DPA ordered the controller to bring its processing of personal data into compliance – which included, among others, erasing the data and providing the addressees of its marketing campaign with all the information required by Article 14. Additionally, the DPA ordered the controller to bring its processing of personal data into compliance – which included, among others, erasing the data and providing the addressees of its marketing campaign with all the information required by Article 14. On the applicable legal regime ==== On the applicable legal regime ==== First, the DPA clarified that the case fell within the scope of both the GDPR and the Article 13 of the ePrivacy Directive (as well as its implementation in Italian law). First, the DPA clarified that the case fell within the scope of both the GDPR and the Article 13 of the ePrivacy Directive (as well as its implementation in Italian law Art. 130 d. lgs. 196\u002F2003. ). The DPA pointed out that the data set, which the controller bought and processed, contained at least some personal data. On these grounds, the DPA held that the case fell within the scope of the GDPR even though the controller’s campaign was B2B in nature. The DPA pointed out that the data set, which the controller bought and processed, contained at least some personal data. On these grounds, the DPA held that the case fell within the scope of the GDPR even though the controller’s campaign was B2B in nature. With regards to the ePrivacy Directive, the DPA observed that Article 13 covers marketing carried out towards subscribers or users!!! of an electronic communications network, and clarified that the notions of “subscriber” or “users” may also cover legal persons. On these grounds, the DPA held that the Article applied to the case at hand regardless of the personal or non-personal nature of the data processed. With regards to the ePrivacy Directive, the DPA observed that Article 13 covers marketing carried out towards subscribers or users The Italian implementation closely follows the wording of the Directive (''\"contraente o utente\"''). of an electronic communications network, and clarified that the notions of “subscriber” or “users” may also cover legal persons. On these grounds, the DPA held that the Article applied to the case at hand regardless of the personal or non-personal nature of the data processed. Lawfulness ==== On lawfulness ==== Article 13 of the ePrivacy Directive requires consent for sending unsolicited marketing emails. In the DPA’s view, this made it unlawful for the controller to rely on legitimate interest as its legal basis. On these grounds, the DPA held that the controller unlawfully processed personal data for marketing purposes. Article 13 of the ePrivacy Directive requires consent for sending unsolicited marketing emails. In the DPA’s view, this made it unlawful for the controller to rely on legitimate interest as its legal basis. On these grounds, the DPA held that the controller unlawfully processed personal data for marketing purposes. ==== On transparency ==== The DPA acknowledged that the controller’s marketing emails contained a privacy notice but found it to be severely lacking. On these grounds, the DPA held that the controller violated [[Article 14 GDPR]] as well as the transparency principle. Transparency ==== On the controller's accountability ==== The DPA acknowledged that the controller’s marketing emails contained a privacy notice but found it to be severely lacking. On these grounds, the DPA held that the controller violated [[Article 14 GDPR|Article 14 GDPR]] as well as the transparency principle. On the controller’s accountability In its defence, the controller pointed out that Apollo had put forward claims that its processing complied with applicable laws and that the data set it sold, could lawfully be used for marketing. The DPA, however, applied the principle of accountability ([[Article 5 GDPR|Article 5(2) GDPR]]) and concluded that the documental or contractual guarantees provided a third-party, did not exempt the controller from assessing the lawfulness of its processing and did not shield the controller from liability. In its defence, the controller pointed out that Apollo had put forward claims that its processing complied with applicable laws and that the data set it sold, could lawfully be used for marketing. The DPA, however, applied the principle of accountability ([[Article 5 GDPR|Article 5(2) GDPR]]) and concluded that the documental or contractual guarantees provided a third-party, did not exempt the controller from assessing the lawfulness of its processing and did not shield the controller from liability. == Comment == == Comment == ''Share your comments here!'' The case is a reminder that in the view of the Garante, Article 13 of the ePrivacy Directive (and its implementation in Italian legislation) may also cover marketing campaigns that do not involve the processing of personal data under the GDPR. == Further Resources == == Further Resources ==","Italy's Garante per la protezione dei dati personali (DPA) has fined a company €1,500 for violating GDPR and the ePrivacy Directive. The violations stemmed from an unsolicited marketing email campaign, where the company unlawfully relied on legitimate interest instead of consent and failed to provide adequate transparency information. The DPA clarified that the ePrivacy Directive's marketing provisions can apply even to B2B campaigns and when personal data is not processed under GDPR.","Italy's DPA fines a company €1,500 for GDPR and ePrivacy violations in B2B marketing.","Help Garante per la protezione dei dati personali (Italy) - 351\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 14:42, 28 August 2026 view sourceCarloc (talk | contribs)728 edits Tag: Decisions [1.0] Latest revision as of 14:58, 28 August 2026 view source Carloc (talk | contribs)728 edits Tag: Visual edit (4 intermediate revisions by the same user not shown)Line 110: Line 110: An individual (the data subject) filed a complaint after receiving one of said emails.An individual (the data subject) filed a complaint after receiving one of said emails. === Holding ====== Holding === Overall, the DPA found violations of Articles 5(1)(a) and 14 GDPR as well as Art. 130 c.1. d. lgs. 196\u002F2003 (i.e.: the Italian implementation of Article 13 of the ePrivacy Directive).Overall, the DPA found violations of Articles 5(1)(a) and 14 GDPR as well as Art. 130 c.1. d. lgs. 196\u002F2003 (i.e.: the Italian implementation of Article 13 of the ePrivacy Directive). The DPA issued a E1,500 fine. In quantifying the fine, the DPA took into account that the controller had taken steps to fix its violations before the decision.The DPA issued a €1,500 fine. In quantifying the fine, the DPA took into account that the controller had taken steps to fix its violations before the decision. Additionally, the DPA ordered the controller to bring its processing of personal data into compliance – which included, among others, erasing the data and providing the addressees of its marketing campaign with all the information required by Article 14.Additionally, the DPA ordered the controller to bring its processing of personal data into compliance – which included, among others, erasing the data and providing the addressees of its marketing campaign with all the information required by Article 14. On the applicable legal regime==== On the applicable legal regime ==== First, the DPA clarified that the case fell within the scope of both the GDPR and the Article 13 of the ePrivacy Directive (as well as its implementation in Italian law).First, the DPA clarified that the case fell within the scope of both the GDPR and the Article 13 of the ePrivacy Directive (as well as its implementation in Italian law\u003Cref>Art. 130 d. lgs. 196\u002F2003.\u003C\u002Fref>). The DPA pointed out that the data set, which the controller bought and processed, contained at least some personal data. On these grounds, the DPA held that the case fell within the scope of the GDPR even though the controller’s campaign was B2B in nature.The DPA pointed out that the data set, which the controller bought and processed, contained at least some personal data. On these grounds, the DPA held that the case fell within the scope of the GDPR even though the controller’s campaign was B2B in nature. With regards to the ePrivacy Directive, the DPA observed that Article 13 covers marketing carried out towards subscribers or users!!! of an electronic communications network, and clarified that the notions of “subscriber” or “users” may also cover legal persons. On these grounds, the DPA held that the Article applied to the case at hand regardless of the personal or non-personal nature of the data processed.With regards to the ePrivacy Directive, the DPA observed that Article 13 covers marketing carried out towards subscribers or users\u003Cref>The Italian implementation closely follows the wording of the Directive (''\"contraente o utente\"'').\u003C\u002Fref> of an electronic communications network, and clarified that the notions of “subscriber” or “users” may also cover legal persons. On these grounds, the DPA held that the Article applied to the case at hand regardless of the personal or non-personal nature of the data processed. Lawfulness==== On lawfulness ==== Article 13 of the ePrivacy Directive requires consent for sending unsolicited marketing emails. In the DPA’s view, this made it unlawful for the controller to rely on legitimate interest as its legal basis. On these grounds, the DPA held that the controller unlawfully processed personal data for marketing purposes.Article 13 of the ePrivacy Directive requires consent for sending unsolicited marketing emails. In the DPA’s view, this made it unlawful for the controller to rely on legitimate interest as its legal basis. On these grounds, the DPA held that the controller unlawfully processed personal data for marketing purposes. ==== On transparency ==== The DPA acknowledged that the controller’s marketing emails contained a privacy notice but found it to be severely lacking. On these grounds, the DPA held that the controller violated [[Article 14 GDPR]] as well as the transparency principle. Transparency==== On the controller's accountability ==== The DPA acknowledged that the controller’s marketing emails contained a privacy notice but found it to be severely lacking. On these grounds, the DPA held that the controller violated [[Article 14 GDPR|Article 14 GDPR]] as well as the transparency principle. On the controller’s accountability In its defence, the controller pointed out that Apollo had put forward claims that its processing complied with applicable laws and that the data set it sold, could lawfully be used for marketing. The DPA, however, applied the principle of accountability ([[Article 5 GDPR|Article 5(2) GDPR]]) and concluded that the documental or contractual guarantees provided a third-party, did not exempt the controller from assessing the lawfulness of its processing and did not shield the controller from liability.In its defence, the controller pointed out that Apollo had put forward claims that its processing complied with applicable laws and that the data set it sold, could lawfully be used for marketing. The DPA, however, applied the principle of accountability ([[Article 5 GDPR|Article 5(2) GDPR]]) and concluded that the documental or contractual guarantees provided a third-party, did not exempt the controller from assessing the lawfulness of its processing and did not shield the controller from liability. == Comment ==== Comment == ''Share your comments here!''The case is a reminder that in the view of the Garante, Article 13 of the ePrivacy Directive (and its implementation in Italian legislation) may also cover marketing campaigns that do not involve the processing of personal data under the GDPR. == Further Resources ==== Further Resources == Latest revision as of 14:58, 28 August 2026 Garante per la protezione dei dati personali - 351\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(1)(a) GDPR Article 14 GDPR Article 5(2) GDPR Article 13 ePrivacy DirectiveArticle 130 d.lgs. 196\u002F2003 Type: Complaint Outcome: Upheld Started: 05.03.2025 Decided: 14.05.2026 Published: Fine: 1500.0 EUR Parties: Ditta individuale Francesco Gagliardi National Case Number\u002FName: 351\u002F2026 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: carloc The DPA fined a marketing company €1,500 for unlawfully sending unsolicited communications in the context of a B2B marketing campaign. Contents 1 English Summary 1.1 Facts 1.2 Holding 1.2.1 On the applicable legal regime 1.2.2 On lawfulness 1.2.3 On transparency 1.2.4 On the controller's accountability 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts An individual company (the controller) engaged in a B2B marketing campaign. To this end, it bought a data set from a third-party: a sales platform called Apollo.io. The set consisted of about 2,500 professional contacts, including email addresses, phone numbers, and personal details of the contacts as well as their role within organizations. It is not known how Apollo acquired the information. The controller then used the data for sending unsolicited marketing communications. The controller relied on its legitimate interest as the legal basis of its legitimate interest. Every email cont","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_351\u002F2026&diff=52825&oldid=52820","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-28T14:58:08+00:00","2026-08-28T16:00:09.824764+00:00",7,[18],{"name":19,"type":20},"Apollo","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]