Back to Feed
PolicyAug 14, 2026

Garante per la protezione dei dati personali (Italy) - 556/2026

TIM S.p.A. fined €9.5M by Italian DPA for unlawful telemarketing and data handling failures.

Summary

The Italian DPA has fined TIM S.p.A. €9,516,000 for unlawful telemarketing practices, inadequate supervision of sales partners, and failures in respecting data subject rights. Investigations revealed that TIM used a process to generate 'Leads' that masked unsolicited promotional calls made without consent, and failed to implement sufficient checks on its partners' activities. Additionally, the company was found to have mishandled data subject rights requests, with users continuing to receive marketing communications even after objecting.

Full text

Help Garante per la protezione dei dati personali (Italy) - 556/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:30, 14 August 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:30, 14 August 2026 Garante per la protezione dei dati personali - 556/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5(2) GDPR Article 24 GDPR Article 28 GDPR Article 5(1) GDPR Article 6 GDPR Article 7 GDPR Article 25 GDPR Article 32 GDPR Article 12(2) GDPR Article 12(3) GDPR Article 130 of the Codice in Materia di Protezione dei Dati Personali Type: Investigation Outcome: Violation Found Started: Decided: 23.07.2026 Published: Fine: 9516000.0 EUR Parties: TIM S.p.A. National Case Number/Name: 556/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ds The DPA fined TIM €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited promotional calls made on behalf of the controller, often to telephone numbers registered in the Public Opt-Out Registry. The investigation revealed that users initially received unsolicited promotional calls from untraceable or spoofed numbers offering the controller’s services. They subsequently received, via SMS or messaging services, a link to an online form which they were invited to complete in order to generate what appeared to be a spontaneous request for a callback, a so-called “Lead”. This was followed by another call from the call centre, this time using a formally registered number. According to the DPA, this procedure was used to conceal the unlawful origin of the initial contact. The controller’s partners presented the Leads as spontaneous requests from users, although they had actually been generated following previous promotional calls made without consent. Orders and activation requests resulting from those contacts were subsequently entered into the controller’s official systems. The DPA also identified significant discrepancies between the number of Leads reported by certain partners and the number of calls they made. In some cases, the number of contacts substantially exceeded the number of declared Leads, while conversion rates were particularly low. The DPA stated that such anomalies should have triggered internal checks, automated alerts and, where appropriate, the immediate suspension of the relevant data flows. The DPA found that the controller’s systems also lacked mechanisms to verify whether the person entering a telephone number into a Lead form was actually the holder of that number. During the investigation, the controller introduced an SMS-based opt-out mechanism under which the number holder had five minutes to reject the callback or withdraw consent. It also introduced measures to monitor IP addresses and restrict bulk submissions of telephone numbers. The investigation further identified problems concerning the exercise of data subject rights. In several cases, users continued to receive promotional communications for months after objecting. Procedures for withdrawing consent or opting out of marketing required users to log into their MyTIM account or use dedicated applications, while requests concerning access, erasure and objection were answered late, incompletely or not at all. The controller argued that the unlawful calls had been made by unknown third parties using numbers outside its official sales network and in breach of its instructions. It also maintained that the Leads appeared formally valid in its systems, that none of the cases examined resulted in the final conclusion of a contract and that its governance framework complied with the Code of Conduct for telemarketing. Holding The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice. It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached Article 5(2) GDPR by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed Article 24 GDPR and Article 28 GDPR. The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain. Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of Article 5(1) GDPR, Article 6 GDPR, Article 7 GDPR and Article 130 of the Italian Data Protection Code. The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed Article 25 GDPR. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed Article 32 GDPR. Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed Article 12(2) GDPR, Article 24 GDPR and the rights of the data subjects. It further found an infringement of Article 12(3) GDPR in relation to requests that were not answered or were answered with unjustified delay. The DPA ordered the controller to amend its procedures for generating Leads and callbacks and to ensure that consent to be contacted could be shown to originate from the actual holder of the number. It also ordered the controller to s

Entities

TIM S.p.A. (vendor)MyTIM (product)