Enel Energia SpA – €79,100,000 Fine (Italy, 2024)

€79,100,000Garante per la protezione dei dati personali8 February 2024Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by agencies that unlawfully performed telemarketing activities. According to the DPA, Enel Energia acquired as many as 978 contracts from four different previously sanctioned companies, even though they did not belong to the energy company’s sales network. Moreover, following subsequent inspections at Enel Energia, the DPA ascertained that the information systems used for customer management and service activation by the company showed the abovementioned serious security shortcomings. Enel failed to put in place all the necessary measures to prevent the unlawful activities of unauthorised agents who fuelled for years an illicit business carried out through nuisance calls, service promotions, and the signing of contracts with no real economic benefits for customers by identifying easy ‘front doors’ in the company’s information systems.

GDPR Articles Cited

AI-verified

Art. 25 GDPR
Art. 28 GDPR
Art. 32 GDPR
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(1) GDPR
Art. 25 GDPR
Art. 28 GDPR
Art. 32 GDPR

Original data from scraper before AI verification against source document.

Source verified 4 March 2026
amount discrepancy
Full Legal Summary

The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by agencies that unlawfully performed telemarketing activities. According to the DPA, Enel Energia acquired as many as 978 contracts from four different previously sanctioned companies, even though they did not belong to the energy company’s sales network. Moreover, following subsequent inspections at Enel Energia, the DPA ascertained that the information systems used for customer management and service activation by the company showed the abovementioned serious security shortcomings. Enel failed to put in place all the necessary measures to prevent the unlawful activities of unauthorised agents who fuelled for years an illicit business carried out through nuisance calls, service promotions, and the signing of contracts with no real economic benefits for customers by identifying easy ‘front doors’ in the company’s information systems.

Related Enforcement Actions (0)

No other enforcement actions found for Enel Energia SpA in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

8 February 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€79,100,000

Enforcement Tracker ID

ETid-2306

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Enel Energia SpA - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: