E.ON Energia spa

€892,783

Insufficient legal basis for data processing

Päätöspäivä

27. marraskuuta 2024

Viranomainen

Italian Data Protection Authority (Garante)

IT

Ala

Transportation and Energy

Maa

IT

Laki

GDPR

Tila

FINAL

Kuvaus

he Italian DPA has imposed a fine of EUR 892,738 on E.ON Energia spa for unlawfully processing personal data for telemarketing. The investigation was triggered by complaints from two individuals who received unsolicited calls and did not receive responses to their requests to exercise their rights under the GDPR. It was found that when the electricity and gas supplies were activated, consents of data subjects were recorded incorrectly. E.ON failed to take appropriate measures to verify the accuracy of the consent given by customers and the corresponding data stored in the systems, which resulted in telemarketing being carried out without a lawful basis. Furthermore, the DPA found that there was a lack of sufficient control and training of the employees responsible for these activities. In another case, E.ON stated that the calls were made in response to a request from the data subject to be contacted, submitted in the context of a Facebook advertising campaign. However, the data subject stated that they were never registered on Facebook. Along with the fine, E.ON was ordered to implement measures to ensure future compliance with data protection regulations.

Oikeudelliset viittaukset

Art. 5Art. 6Art. 7Art. 12Art. 15Art. 22Art. 24Art. 28

Asiat ja rikkomukset

Insufficient legal basis for data processing

Pysy ajan tasalla yksityisyyden suojan valvonnasta

Kunnioitamme yksityisyyttäsi. Yksi sähköpostiviesti kuukaudessa, ei roskapostia, peruuta tilaus milloin tahansa.