[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjuq03WWtS7ESJk8MRLHJwcxkE08L_-eypCJrcIpkfxs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"83609e01-c2f0-4d02-9b62-df3c5a3230cc","italian-dpa-fines-processor-15300-for-unsolicited-marketing-rights-failures-and-unauthorized-sub-pro","63cf5e6e-b547-4ecd-b22c-c2c80c25a0ac","Italian DPA Fines Processor €15,300 for Unsolicited Marketing, Rights Failures, and Unauthorized Sub-Processing","Green Partner violated GDPR by sending promotional communications to an individual registered on Italy's Public Opt-Out Registry, demonstrating a failure to screen contact lists against do-not-contact databases before launching marketing campaigns. Compounding this, the company failed to adequately respond to data subject rights requests, a fundamental GDPR obligation. Most critically, Green Partner engaged a sub-processor without authorization from the data controller, breaching both contractual terms and Article 28 GDPR, which strictly governs processor-to-sub-processor relationships. This case illustrates how GDPR liability can cascade when processors operate beyond their sanctioned boundaries and neglect core compliance controls. Organizations acting as data processors must treat their contractual and regulatory obligations as non-negotiable operational constraints, not administrative formalities.","**Immediate actions:**\n- Scrub all marketing contact lists against the Public Opt-Out Registry (Registro delle Opposizioni) before every campaign launch.\n- Establish a formal data subject rights request (DSAR) intake and response process with tracked SLAs to ensure timely compliance.\n- Audit all current sub-processors to verify each has explicit written authorization from the relevant data controller.\n\n**Long-term improvements:**\n- Embed sub-processor approval workflows into vendor and contract management systems so no engagement can proceed without documented controller consent.\n- Implement a GDPR roles and responsibilities training program specifically for staff handling marketing data and data subject requests.\n- Maintain a continuously updated Record of Processing Activities (RoPA) that maps all processors, sub-processors, and their authorized purposes.\n\n**Detection & monitoring measures:**\n- Deploy automated checks that cross-reference campaign recipient lists against opt-out registries prior to send.\n- Schedule quarterly internal audits of processor-controller contracts to identify unauthorized sub-processing arrangements or scope creep.\n- Log and monitor all data subject rights requests end-to-end to detect response failures before regulatory deadlines are breached.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 6 – Lawfulness of processing","GDPR Article 17 – Right to erasure","GDPR Article 21 – Right to object (including direct marketing)","GDPR Article 28 – Processor obligations and sub-processor authorization","GDPR Article 12 & 13 – Transparency and data subject rights response timelines","NIST SP 800-53 PT-5 – Privacy Notice","NIST SP 800-53 SA-9 – External Information System Services (supply chain oversight)","CIS Control 3 – Data Protection","CIS Control 14 – Security Awareness and Skills Training","ITIL Service Design – Supplier Management","published","2026-08-18T16:20:57.092723+00:00","2026-08-18T16:20:56.805+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10266250&diff=52723&oldid=52697","garante-per-la-protezione-dei-dati-personali-italy-10266250-c79171","Garante per la protezione dei dati personali (Italy) - 10266250",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]