[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3a9c1d6xCTyLVt5CVCNW25mtuCSwH6sqoA2XjqfQbBY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"4e58af4a-ac8e-4db0-89c6-6331e604f6c1","italian-dpa-fines-processor-15300-for-unsolicited-marketing-and-gdpr-rights-failures","7edecfea-bd35-4253-b8a1-67740f0e07c8","Italian DPA Fines Processor €15,300 for Unsolicited Marketing and GDPR Rights Failures","A data processor violated GDPR by making unsolicited promotional calls and sending emails to an individual registered on Italy's opt-out registry, indicating a failure to check suppression lists before initiating marketing campaigns. Compounding this, the processor could not adequately handle the data subject's requests to exercise their rights — such as erasure or objection — revealing a fundamental misunderstanding of processor obligations under GDPR Articles 28 and beyond. This case highlights that GDPR compliance is not merely a legal checkbox but requires operational processes, trained staff, and clear accountability structures. Processors must understand that ignorance of their legal basis and duties does not constitute a defense and can result in both financial penalties and reputational damage.","**Immediate actions:**\n- Validate all marketing contact lists against national opt-out registries (e.g., Italy's Registro delle Opposizioni) before any outreach campaign.\n- Establish a documented, time-bound process for responding to data subject rights requests in compliance with GDPR Article 12 timelines.\n\n**Long-term improvements:**\n- Conduct regular GDPR training for all staff involved in data processing roles, with specific modules on processor duties under Article 28.\n- Implement a Data Processing Agreement (DPA) review cycle to ensure all processors understand their legal bases and obligations.\n- Appoint or designate a responsible compliance contact (e.g., DPO or compliance officer) to oversee rights request handling and marketing consent management.\n\n**Detection & Monitoring measures:**\n- Audit marketing campaign workflows quarterly to verify suppression list integration and consent validity.\n- Log and track all data subject rights requests centrally to ensure none are missed, delayed, or improperly handled.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 6 – Lawfulness of processing","GDPR Article 12 – Transparent information and data subject rights","GDPR Article 17 – Right to erasure","GDPR Article 21 – Right to object","GDPR Article 28 – Processor obligations","GDPR Article 83(4) – Administrative fines for processor violations","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 AT-2 (Literacy Training and Awareness)","CIS Control 14 – Security Awareness and Skills Training","ISO\u002FIEC 27701 – Privacy Information Management (PIMS)","ITIL Service Design – Compliance and Legal Requirements Management","published","2026-08-14T18:20:24.261386+00:00","2026-08-14T18:20:23.996+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10266250&diff=52697&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-10266250-35d1d8","Garante per la protezione dei dati personali (Italy) - 10266250",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"043495a0-67a2-455c-ad3f-62e92ad76640","2026-08-15","morning","ThreatNoir Weekend Brief — August 15","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-15\u002Fthreatnoir-morning-brief-2026-08-15.mp3"]