Back to all lessons
Awareness Lessons
4 months ago

Italian Utility Fined for GDPR Violations: Poor Data Handling and Consent Management

This case highlights critical failures in data protection practices where a utilities company couldn't properly explain their legal basis for collecting personal data used in marketing activities. The company provided contradictory statements about how they acquired customer data and failed to adequately respond to a data subject's access request. Most concerning was the breakdown in consent management between the data controller and processor, creating confusion about lawful data processing. These fundamental GDPR compliance failures demonstrate how poor data governance can lead to regulatory penalties and erode customer trust.

Tactical Insight

Immediate actions

  • Document clear legal basis for all personal data collection and processing activities
  • Review and update data subject request response procedures to ensure compliance
  • Audit all marketing data sources to verify lawful acquisition methods

Long-term improvements

  • Implement comprehensive data processing agreements with all third-party processors
  • Establish regular GDPR compliance training for staff handling personal data
  • Create centralized consent management system to track and manage user permissions

Monitoring measures

  • Conduct quarterly audits of data processing activities and legal basis documentation
  • Monitor data subject request response times and quality metrics
  • Track consent withdrawal requests and ensure timely processing across all systems