Vodafone Italia S.p.A.

€12,251,601

Non-compliance with general data processing principles

决定日期

2020年11月12日

权力

Italian Data Protection Authority (Garante)

IT

部门

Media, Telecoms and Broadcasting

国家

IT

法律

GDPR

现状

FINAL

说明

The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of complaints from data subjects about unsolicited telephone calls, which led to an investigation by the data protection authority. This investigation revealed several violations of the data protection law, including the violation of consent requirements and the violation of general data protection obligations such as accountability. One of the main criticisms made by the Data Protection Agency was the use of fake numbers to make promotional calls by the contracted call centers (i.e. phone numbers not registered with the National Consolidated Registry of Communication Operators). Furthermore, further violations could be found in the handling of contact lists purchased from external providers. Finally, security measures for the management of customer data were also considered inadequate.

法律引文

Art. 5 (1)Art. 6 (1)Art. 7Art. 15 (1)Art. 16Art. 21Art. 24Art. 25 (1)Art. 32Art. 33

问题与违规

Non-compliance with general data processing principles

随时了解隐私执法的最新情况

我们尊重您的隐私。每月一封电子邮件,无垃圾邮件,随时退订。