Enel Energia S.p.A

Ni na voljo

Insufficient legal basis for data processing

Datum odločitve

16. december 2021

Organ

Italian Data Protection Authority (Garante)

IT

Sektor

Transportation and Energy

Država

IT

Zakon

GDPR

Status

FINAL

Opis

Originial fine summary: The Italian DPA has fined Enel Energia S.p.A EUR 26.5 million for numerous breaches of the GDPR. Following a complex preliminary investigation launched after hundreds of reports and complaints from users, the DPA finds that the controller illegally processed the personal data of millions of users for telemarketing purposes. The DPA found, among other things, that data subjects received unsolicited promotional calls in the name of and on behalf of Enel Energia, in some cases even recorded calls. Some of the data subjects still received advertising calls, even though they had already requested Enel Energia to delete their personal data several times or had objected to their processing for advertising purposes. In particular, the DPA found that Enel Energia had not provided data subjects with the required and timely feedback on their requests to exercise their rights of access and opposition. In addition, the DPA found that the company had not sufficiently cooperated with the DPA during the investigation. For example, Enel Energia failed to respond to various inquiries from the DPA. In assessing the fine, the DPA considered the following factors aggravating: the seriousness of the violations, the duration and repetition of the violations, as well as the large number of persons affected and the negligence of the conduct. Update: The Court of Rome overturned the fine of EUR 26.5 million.

Pravne navedbe

Art. 5 (1)Art. 5 (2)Art. 6 (1)Art. 12Art. 13Art. 21Art. 24Art. 25 (1)Art. 30Art. 31Art. 130 (1)

Vprašanja in kršitve

Insufficient legal basis for data processing

Spremljajte novice o uveljavljanju zasebnosti

Spoštujemo vašo zasebnost. Eno e-poštno sporočilo na mesec, brez neželene pošte, odjava kadar koli.