Illumia Spa

€678,897

Insufficient technical and organisational measures to ensure information security

Decision Date

November 13, 2024

Authority

Italian Data Protection Authority (Garante)

IT

Sector

Transportation and Energy

Country

IT

Law

GDPR

Status

FINAL

Description

The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints from users who received unwanted advertising calls from call centers working on behalf of Illumia. The DPA found that the company had not carried out sufficient controls along the entire telemarketing supply chain. Among other things, advertising calls were made without a legal basis, and necessary technical and organizational measures were only implemented after a delay.

Legal Citations

Art. 5 (2)Art. 6Art. 7Art. 24Art. 25Art. 28Art. 32

Issues & Violations

Insufficient technical and organisational measures to ensure information security

Stay Updated on Privacy Enforcement

We respect your privacy. One email per month, no spam, unsubscribe anytime.