[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKJwSQuXj6Nbw0e_3rMC-hCJX1k0uBvsitUTQYqc2QgY":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"29d076ac-965c-42da-8f33-d27a3a89a9f2","Garante per la protezione dei dati personali (Italy) - 556\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-556-2026-70f4cf","← Older revision Revision as of 13:21, 14 August 2026 Line 124: Line 124: }} }} The DPA fined TIM €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights. The DPA fined a telecom provider €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights. == English Summary == == English Summary == Line 147: Line 147: The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice. The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice. It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached [[Article 5 GDPR|Article 5(2) GDPR]] by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed [[Article 24 GDPR|Article 24 GDPR]] and [[Article 28 GDPR|Article 28 GDPR]]. It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached [[Article 5 GDPR|Article 5(2) GDPR]] by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed [[Article 24 GDPR]] and [[Article 28 GDPR]]. The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain. The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain. Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of [[Article 5 GDPR|Article 5(1) GDPR]], [[Article 6 GDPR|Article 6 GDPR]], [[Article 7 GDPR|Article 7 GDPR]] and Article 130 of the Italian Data Protection Code. Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of [[Article 5 GDPR|Article 5(1) GDPR]], [[Article 6 GDPR]], [[Article 7 GDPR]] and Article 130 of the Italian Data Protection Code. The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed [[Article 25 GDPR|Article 25 GDPR]]. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed [[Article 32 GDPR|Article 32 GDPR]]. The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed [[Article 25 GDPR]]. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed [[Article 32 GDPR]]. Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed [[Article 12 GDPR|Article 12(2) GDPR]], [[Article 24 GDPR|Article 24 GDPR]] and the rights of the data subjects. It further found an infringement of [[Article 12 GDPR|Article 12(3) GDPR]] in relation to requests that were not answered or were answered with unjustified delay. Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed [[Article 12 GDPR|Article 12(2) GDPR]], [[Article 24 GDPR]] and the rights of the data subjects. It further found an infringement of [[Article 12 GDPR|Article 12(3) GDPR]] in relation to requests that were not answered or were answered with unjustified delay. The DPA ordered the controller to amend its procedures for generating Leads and callbacks and to ensure that consent to be contacted could be shown to originate from the actual holder of the number. It also ordered the controller to strengthen its supervision of commercial partners and improve its procedures for handling the exercise of data subject rights. The DPA ordered the controller to amend its procedures for generating Leads and callbacks and to ensure that consent to be contacted could be shown to originate from the actual holder of the number. It also ordered the controller to strengthen its supervision of commercial partners and improve its procedures for handling the exercise of data subject rights.","Italy's Garante per la protezione dei dati personali (DPA) has fined TIM €9,516,000 for unlawful telemarketing practices and inadequate supervision of its sales partners. The DPA found that TIM failed to implement effective systems for monitoring its sales network and that its organizational and technical design for accepting leads was inadequate. The ruling also highlighted issues with consent collection, data subject rights handling, and an insufficient opt-out mechanism.","Italy's DPA fines TIM €9.5M for unlawful telemarketing and data handling failures.","Help Garante per la protezione dei dati personali (Italy) - 556\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 12:30, 14 August 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 edits Tag: Decisions [1.0] Latest revision as of 13:21, 14 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 editsmTag: Visual edit Line 124: Line 124: }}}} The DPA fined TIM €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights.The DPA fined a telecom provider €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights. == English Summary ==== English Summary == Line 147: Line 147: The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice.The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice. It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached [[Article 5 GDPR|Article 5(2) GDPR]] by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed [[Article 24 GDPR|Article 24 GDPR]] and [[Article 28 GDPR|Article 28 GDPR]].It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached [[Article 5 GDPR|Article 5(2) GDPR]] by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed [[Article 24 GDPR]] and [[Article 28 GDPR]]. The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain.The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain. Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of [[Article 5 GDPR|Article 5(1) GDPR]], [[Article 6 GDPR|Article 6 GDPR]], [[Article 7 GDPR|Article 7 GDPR]] and Article 130 of the Italian Data Protection Code.Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of [[Article 5 GDPR|Article 5(1) GDPR]], [[Article 6 GDPR]], [[Article 7 GDPR]] and Article 130 of the Italian Data Protection Code. The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed [[Article 25 GDPR|Article 25 GDPR]]. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed [[Article 32 GDPR|Article 32 GDPR]].The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed [[Article 25 GDPR]]. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed [[Article 32 GDPR]]. Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed [[Article 12 GDPR|Article 12(2) GDPR]], [[Article 24 GDPR|Article 24 GDPR]] and the rights of the data subjects. It further found an infringement of [[Article 12 GDPR|Article 12(3) GDPR]] in relation to requests that were not answered or were answered with unjustified delay.Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed [[Article 12 GDPR|Article 12(2) GDPR]], [[Article 24 GDPR]] and the rights of the data subjects. It further found an infringement of [[Article 12 GDPR|Article 12(3) GDPR]] in relatio","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_556\u002F2026&diff=52695&oldid=52694","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-14T13:21:13+00:00","2026-08-14T14:00:22.008421+00:00",7,[18],{"name":19,"type":20},"TIM","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]