Italy Italy

Illumia Spa

678,897 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2024-11-13.

Rank · Sector
#34
of 165 in Transportation and Energy
Rank · Italy
#39
of 543
Rank · All fines
#210
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2024-11-13
Controller / Processor
Illumia Spa
Sector
Transportation and Energy
Quoted Articles
Art. 5 (2) GDPR, Art. 6 GDPR, Art. 7 GPDR, Art. 24 GDPR, Art. 25 GDPR, Art. 28 GDPR, Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Italian DPA has imposed a fine of EUR 678,897 on the energy company Illumia Spa for unlawfully processing personal data for marketing purposes.
The fine follows complaints from users who received unwanted advertising calls from call centers working on behalf of Illumia. The DPA found that the company had not carried out sufficient controls along the entire telemarketing supply chain. Among other things, advertising calls were made without a legal basis, and necessary technical and organizational measures were only implemented after a delay.

Open original source Links to the regulator's original publication or another source.

Related fines