Vodafone Italia S.p.A.

€12,251,601

Non-compliance with general data processing principles

決定日期

2020年11月12日

權限

Italian Data Protection Authority (Garante)

IT

部門

Media, Telecoms and Broadcasting

國家

IT

法律

GDPR

狀態

FINAL

說明

The company was fined EUR 12,251,601 for unlawfully processing personal data of millions of customers for telemarketing purposes. The proceedings were preceded by hundreds of complaints from data subjects about unsolicited telephone calls, which led to an investigation by the data protection authority. This investigation revealed several violations of the data protection law, including the violation of consent requirements and the violation of general data protection obligations such as accountability. One of the main criticisms made by the Data Protection Agency was the use of fake numbers to make promotional calls by the contracted call centers (i.e. phone numbers not registered with the National Consolidated Registry of Communication Operators). Furthermore, further violations could be found in the handling of contact lists purchased from external providers. Finally, security measures for the management of customer data were also considered inadequate.

法律引文

Art. 5 (1)Art. 6 (1)Art. 7Art. 15 (1)Art. 16Art. 21Art. 24Art. 25 (1)Art. 32Art. 33

問題與違規

Non-compliance with general data processing principles

保持最新的隱私權執法資訊

我們尊重您的隱私。每月一封電子郵件,無垃圾郵件,可隨時取消訂閱。