[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpDnwYOZ2HBx7sN0D2WWU17Eyf6xyJ3UySAiGM_Ksd-4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"01b3b5c5-d283-40d6-9263-cb066020dc20","italian-sme-fined-for-unlawful-b2b-marketing-using-purchased-contact-data","36574588-145d-4ab8-b703-eccc4362eee2","Italian SME Fined for Unlawful B2B Marketing Using Purchased Contact Data","Ditta individuale Francesco Gagliardi was fined €1,500 by Italy's Garante after sending unsolicited marketing emails to approximately 2,500 contacts sourced from Apollo.io, incorrectly relying on 'legitimate interest' as the legal basis under GDPR. The Garante ruled that direct marketing communications require explicit consent, not merely a claimed legitimate interest, violating GDPR Articles 5(1)(a) and 14 as well as Italy's ePrivacy implementing legislation. This case highlights how even small businesses are subject to GDPR enforcement and that purchasing third-party contact lists does not transfer lawful processing rights. Misunderstanding the legal bases for marketing is a common and costly compliance error, particularly for organisations without dedicated legal or privacy counsel.","**Immediate actions:**\n- Audit all active marketing campaigns to verify a valid, documented legal basis (consent or legitimate interest with a proper balancing test) exists for every contact list in use.\n- Cease use of any purchased or third-party contact datasets until their provenance and compliance with GDPR lawful-basis requirements have been independently verified.\n\n**Long-term improvements:**\n- Implement a formal data-acquisition policy requiring privacy and legal review before purchasing or ingesting any external contact database.\n- Train marketing and sales staff on the distinction between consent and legitimate interest, including when each applies under GDPR and the ePrivacy Directive.\n- Establish a consent management and records-of-processing inventory so that the legal basis for every marketing list is documented and auditable at all times.\n\n**Compliance & governance measures:**\n- Conduct an annual GDPR compliance review covering all marketing channels, legal bases, and third-party data suppliers.\n- Include contractual GDPR compliance obligations and data-provenance warranties in any agreement with data brokers or contact-list vendors.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 6 – Lawfulness of processing (legal bases)","GDPR Article 7 – Conditions for consent","GDPR Article 14 – Information to be provided where personal data have not been obtained from the data subject","GDPR Article 13 – Transparency obligations","ePrivacy Directive 2002\u002F58\u002FEC – Article 13 (unsolicited communications)","Italy d.lgs. 196\u002F2003 Article 130 – Unsolicited communications","NIST Privacy Framework PR.PO-P1 – Policies and procedures for data processing","CIS Control 3 – Data Protection","ISO\u002FIEC 27701:2019 – Privacy Information Management (clauses 7.2.1 and 7.2.2)","published","2026-08-28T16:21:10.684003+00:00","2026-08-28T16:21:10.37+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_351\u002F2026&diff=52820&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-351-2026-003d44","Garante per la protezione dei dati personali (Italy) - 351\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]