[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJHH9prONQB6w9_Rf5SYzjUxaJksWG1NP-1JfUqxpBvU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"50963944-edb8-4b00-9b09-0191b3d8a6ff","italian-dpa-fines-enel-563k-for-unlawful-marketing-data-processing","1cc8b812-98c4-49c5-8740-1c618e220fc4","Italian DPA Fines Enel €563K for Unlawful Marketing Data Processing","Enel Energia failed to establish lawful consent for direct marketing campaigns, relying on inadequate SMS opt-out systems with unreasonably short windows (as brief as 90 seconds) and insufficient documentation of valid consent. The Italian DPA's decision emphasizes that organizations must implement robust consent mechanisms, preferably double opt-in systems, and maintain proper accountability over data processors. This case demonstrates that weak consent management and poor processor oversight can result in significant regulatory penalties and highlights the importance of designing user-friendly, compliant data processing systems.","**Immediate actions:**\n- Audit all current marketing consent mechanisms to ensure compliance with GDPR requirements\n- Implement reasonable opt-out timeframes (minimum 24-48 hours) for marketing communications\n- Document all consent collection processes with clear audit trails\n\n**Long-term improvements:**\n- Deploy double opt-in systems for all marketing communications to strengthen consent validation\n- Establish comprehensive data processor vetting and monitoring procedures\n- Create user-friendly consent management interfaces that clearly explain data processing purposes\n\n**Compliance measures:**\n- Conduct regular GDPR compliance assessments of marketing operations\n- Train marketing teams on lawful basis requirements and consent management best practices",[12,13,14,15,16],"GDPR Article 6 (Lawfulness of processing)","GDPR Article 7 (Conditions for consent)","GDPR Article 28 (Processor)","CIS Control 3 (Data Protection)","NIST Privacy Framework PR.AC-1","published","2026-03-30T16:09:52.357358+00:00","2026-03-30T16:09:52.214+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10233396&diff=51168&oldid=51164","garante-per-la-protezione-dei-dati-personali-italy-10233396-10","Garante per la protezione dei dati personali (Italy) - 10233396",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]