Mas s.r.l. – €1,800,000 Fine (Italy, 2023)

€1,800,000Garante per la protezione dei dati personali13 April 2023Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Mas s.r.l. was fined €1.8 million for illegally using personal data in door-to-door marketing. The company did not inform consumers about how their data was collected or used. This case highlights the importance of obtaining consent and being transparent with customers about data usage.

What happened

Mas s.r.l. was fined for using personal data for marketing without proper consent or transparency.

Who was affected

Consumers who were targeted in door-to-door marketing campaigns were affected.

What the authority found

The authority ruled that Mas s.r.l. violated data protection rules by failing to obtain consent and not being transparent about data collection.

Why this matters

This case sets a strong precedent for the necessity of consent in data processing. Companies should ensure they have clear consent mechanisms in place before using personal data.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 7(GDPR)
Art. 13(GDPR)
Art. 28(GDPR)
Art. 29(GDPR)
Art. 30(GDPR)
Art. 32(GDPR)
Art. 5(1) GDPR
Art. 5(1)(a) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1) GDPR
Art. 5(2) GDPR
Art. 6(GDPR)
Art. 7(GDPR)
Art. 13(GDPR)
Art. 28(GDPR)
Art. 29(GDPR)
Art. 30(GDPR)
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 130 c. 3 D. lgs. 196/2003

Entities Involved

Mas s.r.l.
Mas s.r.l.s.
Sesta Impresa s.r.l.
Arnia SocCoop
Source verified 2 April 2026
articles corrected
national law identified
entity split needed
scope corrected
Full Legal Summary
Detailed

In February 2021, the Italian Financial Police (Guardia di Finanza) informed the Italian DPA that two related companies, MAS S.R.L. and MAS S.R.L.S., were engaging in door-to-door marketing and ilegally using personal data to promote and offer contracts with electric companies. Initially, the DPA opened an investigation only against the two companies. However, the investigations revealed a complex system of direct and indirect contractual relationships, with two companies in the energy sector as final recipients of said marketing services: HERA COMM and ENEL ENERGIA. Operating as part of that system, MAS S.R.L.S. first bought personal data bases from an Italian and a Spanish company and also from an unidentified vendor on Facebook. Then, together with MAS S.R.L., it processed these data for door-to-door marketing on behalf of the electric companies, without telling consumers that they were mere intermediaries. Additionally, the companies did not tell them how they collected their personal data. Moreover, MAS S.R.L. and MAS S.R.L.S. shared the collected personal data with telemarketing companies SESTA IMPRESA and ARNIA, that further processed the data for telephone advertising. During the investigation, no proof of consumer consent was provided. The DPA also found that SESTA IMPRESA got the credentials to access ENEL's infromation systems and shared them with ARNIA. In turn, ARNIA used these credentials to upload the signed contracts into the system without authorization from ENEL. None of the telemarketing companies had a written contract with ENEL appointing them as processors. Although ARNIA had been appointed as a processor by SESTA in 2019, none of the other companies had signed data processing or joint controllership agreements. They were also not appointed as processors or sub-processors by other intermediaries nor by the final customers HERA COMM and ENEL. The DPA also verified that the marketing activities involved a large number of consumers as ARNIA up

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

13 April 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€1,800,000

GDPRhub ID

gdprhub-6023

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Mas s.r.l. - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: