Illumia Spa
Insufficient technical and organisational measures to ensure information security
Datum för beslut
13 november 2024
Myndighet
Italian Data Protection Authority (Garante)
IT
Sektor
Transportation and Energy
Land
IT
Lag
GDPRStatus
FINALBeskrivning
The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes. The fine follows complaints from users who received unwanted advertising calls from call centers working on behalf of Illumia. The DPA found that the company had not carried out sufficient controls along the entire telemarketing supply chain. Among other things, advertising calls were made without a legal basis, and necessary technical and organizational measures were only implemented after a delay.