Vodafone Italy S.p.A – €12,250,601 Fine (Italy, 2020)

€12,250,601Garante per la protezione dei dati personali12 November 2020Italy
final
ePrivacy
Fine

Vodafone Italy was fined over 12 million euros for sending unwanted promotional messages and for not properly protecting user data. This matters because it shows that companies must respect people's privacy and secure their information. Small businesses should ensure they have clear consent before contacting customers and protect their data properly.

What happened

Vodafone Italy sent unwanted promotional communications and failed to secure user data access.

Who was affected

Customers who received unwanted messages and had their data accessed without authorization were affected.

What the authority found

The authority found that Vodafone Italy did not comply with data protection rules regarding promotional communications and data security.

Why this matters

This case highlights the importance of obtaining consent for marketing and securing user data. It serves as a warning for companies to strengthen their data protection practices.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 16(GDPR)
Art. 21(GDPR)
Art. 24(GDPR)
Art. 32(GDPR)
Art. 15(1) GDPR
Art. 25(1) GDPR
Art. 33(1) GDPR
View original scraped data
Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 15(1) GDPR
Art. 16(GDPR)
Art. 21(GDPR)
Art. 24(GDPR)
Art. 25(1) GDPR
Art. 32(GDPR)
Art. 33(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
scope corrected
Full Legal Summary
Detailed

The Garante per la Protezione dei Dati Personali, Italy’s DPA, led an investigation into Vodafone Italy S.p.A following various complaints by Vodafone users and non-users, which highlighted multiple issues on the phone company’s practices. The first group of claimants complained about constant unwanted promotional phone calls and SMS from Vodafone, with one example being a person claiming that they have been receiving at least 4/5 messages a month by Vodafone since 2018, even after he communicated to the company that he no longer wanted to receive such messages. Vodafone blamed this last mishap on a “system error” that failed to register the client’s request to stop the promotional messages. The second set of complaints concerned the way that the company stored their client’s data. More specifically, costumers complained about being approached by Vodafone operators, usually after reporting issues with their internet service. However, it turned out that those were call-centres that worked for other phone companies or third party callers that used Vodafone’s logo in their WhatsApp profile. These unauthorized individuals would often ask about the issues the users reported, point out that Vodafone would increase their costumer service fees and offer to subscribe the user to a different phone provider. Other times, they would just request for the user’s IDs, possibly for fraudulent or phishing purposes. Vodafone claimed to have been aware of these practices in the past, confirmed that those were indeed unauthorized parties under false pretences, and explained that they were trying to improve security on their databases by applying 2 Factor Authentication. Lastly, several users complained that Vodafone was not responding appropriately to their requests in exercise of their rights under Articles 15-22 GDPR. For example, one user complained that Vodafone had not replied at all to a request sent to them via email. Another one explained that Vodafone did reply, but did

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Vodafone Italy S.p.A in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

12 November 2020

Authority

Garante per la protezione dei dati personali

Fine Amount

€12,250,601

GDPRhub ID

gdprhub-2909

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Vodafone Italy S.p.A - Italy (2020). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: