Italy Italy

Axpo Italia Spa

10,000,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2023-09-28.

Rank · Sector
#7
of 167 in Transportation and Energy
Rank · Italy
#8
of 543
Rank · All fines
#46
of 3,050

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2023-09-28
Controller / Processor
Axpo Italia Spa
Sector
Transportation and Energy
Quoted Articles
Art. 5 (1) a), d) GDPR, Art. 5 (2) GDPR, Art. 24 (2) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa.

The DPA had received numerous complaints from data subjects who complained that, without their knowledge, electricity and gas contracts had been activated in their own names, of which they had only learned after receiving termination letters from the previous supplier or reminders to pay outstanding bills. They also discovered that their personal data provided in the contract (e.g., email address, phone number and utility number) was incorrect or outdated.

During its investigation, the DPA found that the controller had been acquiring new electricity and gas supply contracts through a network of approximately 280 vendors without ensuring that the data entered into the database by the vendors actually corresponded to utility users.

This resulted in unsolicited contracts that often contained inaccurate and outdated personal data.

Open original source Links to the regulator's original publication or another source.

Related fines