Hera Comm S.p.A. – €5,000,000 Fine (Italy, 2024)

€5,000,000Garante per la protezione dei dati personali17 July 2024Italy
final
ePrivacy
Fine

Hera Comm S.p.A. was fined €5 million for sending documents to people who never agreed to an energy supply contract. This case matters because it shows that companies must get proper consent before contacting potential customers. Website operators should be careful about how they collect and use personal information to avoid similar issues.

What happened

Hera Comm S.p.A. sent documents to individuals about an energy contract without their consent or prior contact.

Who was affected

Individuals who received unsolicited documents from Hera Comm S.p.A. were affected.

What the authority found

The Italian DPA found that Hera Comm S.p.A. violated GDPR by failing to obtain valid consent before processing personal data and not responding to user rights requests.

Why this matters

This case serves as a reminder for companies to ensure they have explicit consent before using personal data for marketing or contract purposes.

GDPR Articles Cited

AI-verified

Art. 15(GDPR)
Art. 24(GDPR)
Art. 32(GDPR)
Art. 5(2) GDPR
Art. 12(3) GDPR
Art. 28(1) GDPR
View original scraped data
Art. 5(2) GDPR
Art. 12(3) GDPR
Art. 15(GDPR)
Art. 24(GDPR)
Art. 28(1) GDPR
Art. 32(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
articles corrected
national law identified
scope corrected
Full Legal Summary
Detailed

The DPA received several complaints from data subjects concerning a major Italian energy provider. They argued that they received some documents from the controller concerning the activation of an energy supply contract even if they had never had any contact with the controller or expressed their willingness to enter in such a contract. Furthermore, some data subjects complained that they exercised their Chapter III GDPR rights but obtained no answer from the controller. Therefore, the DPA opened an investigation, which showed that the controller outsourced their door-to-door advertising activities to several companies, that had been appointed as processors. When a data subject accepted to enter into the energy supply contract, the contract was hand signed by the data subject and a copy of their ID card was acquired by the processor. The investigation further showed that some employees of the processors forged the signatures of data subjects. The controller implemented some practices to monitor the processors’ compliance with its internal regulation. More specifically, after the processor uploaded the contract in the appropriate online platform the controller called the data subject’s number to ask if they had the real intention of entering in the contract (“check call”). Moreover, the controller also sent a “welcome letter” to the address provided in the contract. However, if the data subject did not answer the phone, only in very few cases the consequence was that the contract was then discarded. Moreover, as for data retention, the controller pointed out that data are kept for 10 years and that it does not have any other further policy since it would be too expensive and complex to implement it. Finally, concerning the choice of the processors, the controller said that it had not conducted any audit on how they operate. On the processors First, the DPA noted that the processing at hand had been carried out by some processors. The DPA found that these processi

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Related Enforcement Actions (0)

No other enforcement actions found for Hera Comm S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

17 July 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€5,000,000

GDPRhub ID

gdprhub-8295

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Hera Comm S.p.A. - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: