Illumia Spa
Insufficient technical and organisational measures to ensure information security
Decision Date
13 de novembro de 2024
Authority
Italian Data Protection Authority (Garante)
IT
Sector
Transportation and Energy
Country
IT
Law
GDPRStatus
FINALDescription
The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints from users who received unwanted advertising calls from call centers working on behalf of Illumia. The DPA found that the company had not carried out sufficient controls along the entire telemarketing supply chain. Among other things, advertising calls were made without a legal basis, and necessary technical and organizational measures were only implemented after a delay.