E.ON Energia – €892,738 Fine (Italy, 2024)

€892,738Garante per la protezione dei dati personali27 November 2024Italy
final
ePrivacy
Fine

E.ON Energia faced a fine for using third-party cookies without getting consent from users. This is important because it shows that companies must ask for permission before tracking users online. Businesses should review their cookie policies to comply with privacy regulations.

What happened

E.ON Energia used third-party cookies for tracking without obtaining user consent.

Who was affected

Website visitors whose data was tracked by E.ON Energia's cookies were affected.

What the authority found

The authority ruled that E.ON violated GDPR by failing to secure consent for using cookies.

Why this matters

This ruling reinforces the need for businesses to implement clear consent mechanisms for cookies. Companies should ensure they are transparent about data collection practices to avoid future penalties.

GDPR Articles Cited

AI-verified

Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 12(GDPR)
Art. 15(GDPR)
Art. 22(GDPR)
Art. 24(GDPR)
View original scraped data
Art. 5(GDPR)
Art. 6(GDPR)
Art. 7(GDPR)
Art. 12(GDPR)
Art. 15(GDPR)
Art. 22(GDPR)
Art. 24(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
scope corrected
Full Legal Summary
Detailed

After two different data subjects advanced two different complaints against the energy provider E.ON Energia, the controller, the DPA decided to merge the two complaints. The first complaint concerned a marketing call to the data subject, during which she found out that the controller was aware of her birth data, as well as contact data, including her work email. During the marketing call, the operator told the data subject that such contact information had been provided by the data subject herself through an advertising campaign on Facebook. However, the data subject does not even have a Facebook account. The data subject advanced an access request with the controller. The DPA thus contacted the controller to access information relating to the data processing of the first data subject’s data. The controller simply replied that it was likely that the data was collected from a “third party”. In relation to the lack of reply to the data subject, the controller stated that that was a simple human mistake. {{DPAdecisionBOX |Jurisdiction=Italy |DPA-BG-Color=background-color:#095d7e; |DPAlogo=LogoIT.png |DPA_Abbrevation=Garante per la protezione dei dati personali |DPA_With_Country=Garante per la protezione dei dati personali (Italy) |Case_Number_Name=10097012 |ECLI= |Original_Source_Name_1=Garante |Original_Source_Link_1=https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10097012 |Original_Source_Language_1=Italian |Original_Source_Language__Code_1=IT |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint |Outcome=Upheld |Date_Started= |Date_Decided=27.11.2024 |Date_Published= |Year=2024 |Fine=892.738,00 |Currency=EUR |GDPR_Article_1=Article 5 GDPR |GDPR_Article_Link_1=Article 5 GDPR |GDPR_Article_2=Article 6 GDPR |GDPR_Article_Link_2=Article 6 GDPR |GDPR_Article_3=Article 7 GDPR |GDPR_Article_Link_3=Article 7 GDPR |GDPR_Article_4=Article 12 GDPR |GDPR_Article_Link_4=Ar

Violations (1)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for E.ON Energia in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

27 November 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€892,738

GDPRhub ID

gdprhub-8860

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. E.ON Energia - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: