Back to all lessons
Awareness Lessons
4 months ago

Italian Utility Fined €15,000 for GDPR Violations in Direct Marketing and Data Subject Rights

Nuova Corrente S.r.l. violated GDPR by conducting unlawful direct marketing without proper legal basis and failing to adequately respond to a data subject access request. The company provided contradictory information about how they acquired personal data and improperly delegated critical data processing decisions to their processor, Joseph Agency S.r.l.s. This case demonstrates that organizations cannot simply pass responsibility for GDPR compliance to their data processors and must maintain clear records of lawful processing activities. The €15,000 fine serves as a reminder that even smaller violations can result in regulatory action and reputational damage.

Tactical Insight

Immediate actions

  • Conduct audit of all direct marketing activities to ensure valid legal basis exists
  • Review and update data subject access request procedures with clear timelines
  • Document all lawful bases for processing personal data with supporting evidence

Long-term improvements

  • Implement comprehensive data processing records system with acquisition sources
  • Establish clear contractual boundaries between controller and processor responsibilities
  • Train staff on GDPR requirements for marketing consent and data subject rights

Compliance measures

  • Set up regular internal audits of data processing activities and legal bases
  • Create standardized response templates for data subject access requests
  • Implement consent management system for all marketing communications