TIM Fined €9.5M for Unlawful Telemarketing and Poor Sales Partner Oversight
Italy's data protection authority fined TIM €9,516,000 after finding systemic failures in how the telecom giant managed its third-party sales network and handled personal data for marketing purposes. The core issues included inadequate consent collection, failure to honour opt-out requests, and a lack of effective monitoring and oversight of sales partners who were processing personal data on TIM's behalf. This case illustrates that data controllers cannot outsource accountability — they remain fully liable for the actions of processors and partners in their supply chain. The fine underscores that technical and organisational measures must be actively designed, tested, and audited, not merely documented on paper. Regulators are increasingly scrutinising the entire data supply chain, making third-party governance a critical compliance obligation.
Tactical Insight
Immediate actions
- Audit all active third-party sales partners and processors to verify they operate under valid, GDPR-compliant Data Processing Agreements (DPAs).
- Implement and test a robust opt-out/suppression mechanism to ensure marketing stops within regulatory timeframes upon request.
- Review all consent collection flows to confirm they meet the standards of freely given, specific, informed, and unambiguous consent.
Third-party & supply chain governance
- Establish a formal vendor risk management programme that includes periodic audits of sales partners' data handling practices.
- Require partners to submit regular compliance attestations and flag anomalies in lead generation volumes or consent rates.
- Include contractual rights to audit, suspend, or terminate partners who breach data protection obligations.
Long-term improvements
- Deploy centralised logging and monitoring of all lead intake and consent records to create a defensible audit trail.
- Conduct annual Data Protection Impact Assessments (DPIAs) on telemarketing processes and lead-generation systems.
- Train sales and marketing teams on GDPR obligations, with specific modules covering consent validity and data subject rights handling.