Ediscom S.p.A. – €300,000 Fine (Italy, 2023)

€300,000Garante per la protezione dei dati personali23 February 2023Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Ediscom S.p.A. was fined for continuing to use personal data even after users withdrew their consent. This is significant because it shows that companies must respect users' choices regarding their personal information.

What happened

Ediscom S.p.A. was fined for using personal data after users had requested its deletion.

Who was affected

Individuals who requested to stop receiving marketing communications from Ediscom S.p.A. but continued to be contacted.

What the authority found

The Italian data protection authority ruled that Ediscom S.p.A. violated data protection rules by not honoring users' requests to withdraw consent.

Why this matters

This case underscores the importance of respecting user consent and highlights the need for companies to have effective processes in place for managing consent withdrawals.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 13(GDPR)
Art. 14(GDPR)
Art. 24(GDPR)
Art. 25(GDPR)
View original scraped data
Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 13(GDPR)
Art. 14(GDPR)
Art. 24(GDPR)
Art. 25(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
articles corrected
national law identified
scope corrected
Full Legal Summary
Detailed

The controller – Ediscom S.p.A. – was a marketing company whose business consisted in contacting potential customers on behalf of third vendors through sms, emails and automated calls. In order to conduct this activity, the company made use of an extensive database including contact details of more than 21 million people. Personal data were collected both directly by Ediscom and by third parties. In general, Ediscom acknowledged to act as a controller. However, in some cases, Ediscom rented databases from third parties with an aim of monetising them. Although costs and profits were shared, Ediscom considered itself a processor on behalf of the owners of such databases. Ediscom regularly received withdrawals of consent and erasure requests. As Ediscom relied on several databases with partial overlap of data, it usually put these requests in blacklists in order to avoid to reimport the same data from another source – and use them again. Whenever it considered to operate as a processor, Ediscom notified the original controller about erasure or withdrawal of consent requests. Some data subjects claimed to have objected to the processing for marketing purposes. However, they still received calls and messages from Ediscom. In the context of these complaints, the Italian DPA started a broader investigation about the Ediscom’s business practices. The investigation concerned both the websites used by the controller to directly collect personal data and personal data disclosed to Ediscom by third parties. On several websites managed by the Ediscom, users were invited to take part to lotteries or to subscribe to cooking or health newsletters. Theoretically, users could choose whether the Ediscom was allowed to use and share their data for marketing purposes. In practice, the supervisory authority identified numerous GDPR violations. Several GDPR infringements could also be found with regard to personal data originally collected by third parties. Data directly collected by t

Violations (4)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Cookies Persist After Rejection
critical

Tracking cookies remain active or are re-placed even after the user explicitly rejects them.

Art. 6(1) GDPR

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Ediscom S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

23 February 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€300,000

GDPRhub ID

gdprhub-5831

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Ediscom S.p.A. - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: