E.ON Energia spa

€892,783

Insufficient legal basis for data processing

Otsuse kuupäev

27. november 2024

Ametiasutus

Italian Data Protection Authority (Garante)

IT

Sektor

Transportation and Energy

Riik

IT

Seadus

GDPR

Staatus

FINAL

Kirjeldus

he Italian DPA has imposed a fine of EUR 892,738 on E.ON Energia spa for unlawfully processing personal data for telemarketing. The investigation was triggered by complaints from two individuals who received unsolicited calls and did not receive responses to their requests to exercise their rights under the GDPR. It was found that when the electricity and gas supplies were activated, consents of data subjects were recorded incorrectly. E.ON failed to take appropriate measures to verify the accuracy of the consent given by customers and the corresponding data stored in the systems, which resulted in telemarketing being carried out without a lawful basis. Furthermore, the DPA found that there was a lack of sufficient control and training of the employees responsible for these activities. In another case, E.ON stated that the calls were made in response to a request from the data subject to be contacted, submitted in the context of a Facebook advertising campaign. However, the data subject stated that they were never registered on Facebook. Along with the fine, E.ON was ordered to implement measures to ensure future compliance with data protection regulations.

Õiguslikud viited

Art. 5Art. 6Art. 7Art. 12Art. 15Art. 22Art. 24Art. 28

Probleemid ja rikkumised

Insufficient legal basis for data processing

Privaatsuse jõustamise kohta ajakohastatud teave

Me austame teie privaatsust. Üks e-kiri kuus, ei ole rämpsposti, loobuda tellimusest igal ajal.