E.ON Energia spa

€892,783

Insufficient legal basis for data processing

決定日期

2024年11月27日

權限

Italian Data Protection Authority (Garante)

IT

部門

Transportation and Energy

國家

IT

法律

GDPR

狀態

FINAL

說明

he Italian DPA has imposed a fine of EUR 892,738 on E.ON Energia spa for unlawfully processing personal data for telemarketing. The investigation was triggered by complaints from two individuals who received unsolicited calls and did not receive responses to their requests to exercise their rights under the GDPR. It was found that when the electricity and gas supplies were activated, consents of data subjects were recorded incorrectly. E.ON failed to take appropriate measures to verify the accuracy of the consent given by customers and the corresponding data stored in the systems, which resulted in telemarketing being carried out without a lawful basis. Furthermore, the DPA found that there was a lack of sufficient control and training of the employees responsible for these activities. In another case, E.ON stated that the calls were made in response to a request from the data subject to be contacted, submitted in the context of a Facebook advertising campaign. However, the data subject stated that they were never registered on Facebook. Along with the fine, E.ON was ordered to implement measures to ensure future compliance with data protection regulations.

法律引文

Art. 5Art. 6Art. 7Art. 12Art. 15Art. 22Art. 24Art. 28

問題與違規

Insufficient legal basis for data processing

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。