Enel Energia SpA

€79,100,000

Insufficient technical and organisational measures to ensure information security

Ngày ra quyết định

8 tháng 2, 2024

Thẩm quyền

Italian Data Protection Authority (Garante)

IT

Ngành

Transportation and Energy

Quốc gia

IT

Luật

GDPR

Trạng thái

FINAL

Mô tả

The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by agencies that unlawfully performed telemarketing activities. According to the DPA, Enel Energia acquired as many as 978 contracts from four different previously sanctioned companies, even though they did not belong to the energy company’s sales network. Moreover, following subsequent inspections at Enel Energia, the DPA ascertained that the information systems used for customer management and service activation by the company showed the abovementioned serious security shortcomings. Enel failed to put in place all the necessary measures to prevent the unlawful activities of unauthorised agents who fuelled for years an illicit business carried out through nuisance calls, service promotions, and the signing of contracts with no real economic benefits for customers by identifying easy ‘front doors’ in the company’s information systems.

Trích dẫn pháp lý

Art. 5 (1)Art. 5 (2)Art. 24 (1)Art. 25Art. 28Art. 32

Vấn đề & Vi phạm

Insufficient technical and organisational measures to ensure information security

Cập nhật thông tin về việc thực thi quy định bảo vệ dữ liệu cá nhân

Chúng tôi tôn trọng quyền riêng tư của bạn. Chỉ một email mỗi tháng, không spam, có thể hủy đăng ký bất cứ lúc nào.