Edison Energia S.p.A.

€4,900,000

Non-compliance with general data processing principles

결정 날짜

2022년 12월 15일

권한

Italian Data Protection Authority (Garante)

IT

섹터

Transportation and Energy

국가

IT

법률

GDPR

상태

FINAL

설명

The Italian DPA has fined Edison Energia S.p.A. EUR 4.9 million. Several person had filed complaints with the DPA regarding unlawful marketing activities of the company. During its investigation, the DPA found that the company contacted data subjects by telephone for marketing purposes without their consent. For this purpose, the company used contact lists from third parties, which in many cases, however, did not contain the free, specific, informed and documented consent of the users to the disclosure of personal data. The DPA also found that Edison Energia did not provide data subjects with a direct and easy way to exercise their right to object. In addition, Edison Energia failed to respond to data subject requests in a timely manner in several cases. In addition, the DPA found that users of the app and website simultaneously consented to the use of their data for both marketing and profiling purposes. The DPA found that such consent did not correspond to voluntary and specific consent for different purposes. Finally, the DPA found that Edison Energia failed to provide data subjects with transparent information about the processing of their personal data.

법적 인용

Art. 5 (1)Art. 5 (2)Art. 6Art. 7Art. 12 (1)Art. 21 (2)Art. 24 (1)Art. 25 (1)

문제 및 위반 사항

Non-compliance with general data processing principles

개인정보 보호 정책 시행에 대한 최신 정보

당사는 사용자의 개인정보를 존중합니다. 한 달에 한 번, 스팸 없이, 언제든지 구독을 취소할 수 있습니다.