TIM (telecommunications operator) – €27,800,000 Fine (Italy, 2020)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Italy's data protection authority fined TIM nearly EUR 28 million for sending unwanted marketing messages and mishandling personal data. TIM failed to get proper consent from users and didn't protect their data well enough. This case is important because it shows companies must respect people's privacy and have clear data practices.
What happened
TIM sent unsolicited marketing messages and failed to properly manage user data.
Who was affected
People who received unwanted marketing calls or messages from TIM and those whose data was mishandled.
What the authority found
The authority found TIM violated GDPR by not having valid consent for marketing and failing to protect personal data adequately.
Why this matters
This case highlights the need for companies to ensure they have clear consent for marketing and robust data protection measures. It serves as a warning to businesses about the importance of respecting user privacy and data rights.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made without the consent of the data subjects or despite their registration in the public register of objections. Furthermore, irregularities in data processing in connection with competitions were also complained about. In addition, incorrect and non-transparent information on data processing was provided in Apps provided by the Company and invalid methods of consent were used. In some cases, paper forms requesting one single consent were used for various purposes, including marketing. Furthermore, data was kept longer than necessary and thus violated deletion periods. For these violations, the telecommunications company received a fine of EUR 27.8 million. Among other things, the fine was imposed for: lack of consent for marketing activities (telemarketing and cold calling), addressing of data subjects who asked not to be contacted with marketing offers, invalid consents collected in TIM apps, lack of appropriate security measures to protect personal data (including incorrect exchange of blacklists with call centres), lack of clear data retention periods. The supervisory authority also imposed 20 corrective measures on TIM, prohibiting the use of personal data for marketing purposes from those who had refused to receive promotional calls from the call centres.
Related Enforcement Actions (0)
No other enforcement actions found for TIM (telecommunications operator) in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
15 January 2020
Authority
Garante per la protezione dei dati personali
Fine Amount
€27,800,000
Enforcement Tracker ID
ETid-189
About this data
Cite as: Cookie Fines. TIM (telecommunications operator) - Italy (2020). Retrieved from cookiefines.eu
Last updated: