Tiscali Italia S.p.A. – €100,000 Fine (Italy, 2023)

€100,000Garante per la protezione dei dati personali18 July 2023Italy
final
ePrivacy
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Tiscali Italia S.p.A. was fined EUR 100,000 for failing to provide clear information and consent options for its marketing practices. This ruling is significant because it highlights the importance of transparency in how companies handle personal data for marketing purposes.

What happened

Tiscali Italia S.p.A. violated rules regarding disclosure and consent for data processing in its marketing activities.

Who was affected

Customers and potential customers of Tiscali Italia who received marketing communications were affected.

What the authority found

The Italian Data Protection Authority ruled that Tiscali did not comply with principles of fairness and transparency in data processing.

Why this matters

This case underscores the need for companies to be clear and upfront about how they use personal data for marketing. Businesses should review their consent processes to avoid similar issues.

GDPR Articles Cited

AI-verified

Art. 7(GDPR)
Art. 24(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(b) GDPR
Art. 5(2) GDPR
Art. 12(1) GDPR
Art. 13(2) GDPR
View original scraped data
Art. 5(1)(b) GDPR
Art. 5(1)(a) GDPR
Art. 5(2) GDPR
Art. 7(GDPR)
Art. 12(1) GDPR
Art. 13(2) GDPR
Art. 24(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 130(4) Codice Privacy
Source verified 3 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

On 3-5 May 2022, as part of the control of marketing and profiling activities conducted by telephone companies, an inspection was directed at Tiscali Italia S.p.A. (the “Controller”). During the investigation, the Italian Data Protection Authority (DPA) found several issues concerning, among the others, the controller’s disclosure and consent for data processing, the call back service by pop-up, the use of so-called "soft spam", the management of denials and objections to processing and the data retention for marketing and profiling purposes. Following the investigation, on 23 June 2022, the controller sent a note to the DPA explaining the work carried out to address the criticisms raised. Thus, on 14 October 2022, the DPA requested further information and proof of the changes carried out. Following the documents provided by the controller, the DPA concluded the following on each point of contention: On the disclosure and consent for data processing: Violation of the principles of fairness and transparency, as stipulated by Article 5(1)(a) GDPR, Article 12(1) GDPR, as well as Article 13(2) GDPR due to the lack of information on the period of data retention for marketing purposes and of the underlying profiling. Secondly, on the call back service by pop-up: No violation of Article 5(1)(a) GDPR and Article 12(1) GDPR , given that the controller addressed the inconsistencies between the consent acquired through the call-back pop-up and that explained in the information notice. Thirdly, on the use of so-called "soft spam": Violation of [https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29.pdf/b1787d6b-6bce-07da-a38f-3742e3888c1d?version=6.0 Article 130(4) of the Italian Privacy Code] since the controller was sending promotional text messages rather than e-mails to customers who had not given consent for marketing purposes. Fourthly, on the management of denials and objections to processing: Violation

Violations (1)

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Tiscali Italia S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

18 July 2023

Authority

Garante per la protezione dei dati personali

Fine Amount

€100,000

GDPRhub ID

gdprhub-6239

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Tiscali Italia S.p.A. - Italy (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: