Illumia Spa
Insufficient technical and organisational measures to ensure information security
Otsuse kuupäev
13. november 2024
Ametiasutus
Italian Data Protection Authority (Garante)
IT
Sektor
Transportation and Energy
Riik
IT
Seadus
GDPRStaatus
FINALKirjeldus
The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints from users who received unwanted advertising calls from call centers working on behalf of Illumia. The DPA found that the company had not carried out sufficient controls along the entire telemarketing supply chain. Among other things, advertising calls were made without a legal basis, and necessary technical and organizational measures were only implemented after a delay.