TIM S.p.A. – €9,516,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
TIM S.p.A. was fined for making unsolicited promotional calls to people who opted out of such communications. This ruling matters because it highlights the need for companies to respect users' choices regarding marketing. Businesses should ensure they follow opt-out requests to avoid penalties.
What happened
TIM S.p.A. made unsolicited promotional calls to numbers registered in the Public Opt-Out Registry.
Who was affected
Individuals who received unwanted marketing calls despite opting out were affected.
What the authority found
The Italian data protection authority found that TIM S.p.A. violated GDPR rules by not respecting opt-out requests.
Why this matters
This case serves as a reminder for companies to honor user preferences regarding marketing communications. Proper consent mechanisms are crucial.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited promotional calls made on behalf of the controller, often to telephone numbers registered in the Public Opt-Out Registry. The investigation revealed that users initially received unsolicited promotional calls from untraceable or spoofed numbers offering the controller’s services. They subsequently received, via SMS or messaging services, a link to an online form which they were invited to complete in order to generate what appeared to be a spontaneous request for a callback, a so-called “Lead”. This was followed by another call from the call centre, this time using a formally registered number. According to the DPA, this procedure was used to conceal the unlawful origin of the initial contact. The controller’s partners presented the Leads as spontaneous requests from users, although they had actually been generated following previous promotional calls made without consent. Orders and activation requests resulting from those contacts were subsequently entered into the controller’s official systems. The DPA also identified significant discrepancies between the number of Leads reported by certain partners and the number of calls they made. In some cases, the number of contacts substantially exceeded the number of declared Leads, while conversion rates were particularly low. The DPA stated that such anomalies should have triggered internal checks, automated alerts and, where appropriate, the immediate suspension of the relevant data flows. The DPA found that the controller’s systems also lacked mechanisms to verify whether the person entering a telephone number into a Lead form was actually the holder of that number. During the investigation, the controller introduced an SMS-based opt-out mechanism under which the number holder had five minutes to reject the callback or withdraw consent. It als
Related Enforcement Actions (3)
Other enforcement actions involving TIM S.p.A. in IT
Fine
€9.5M
Details
Fine Date
23 July 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€9,516,000
GDPRhub ID
gdprhub-10189About this data
Cite as: Cookie Fines. TIM S.p.A. - Italy (2026). Retrieved from cookiefines.eu
Last updated: