Italy Italy

Interflora Italia S.p.A.

40,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2025-03-13.

Rank · Sector
#120
of 595 in Industry and Commerce
Rank · Italy
#148
of 543
Rank · All fines
#831
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2025-03-13
Controller / Processor
Interflora Italia S.p.A.
Sector
Industry and Commerce
Quoted Articles
Art. 5 (1) a), b) GDPR, Art. 6 (1) a) GDPR, Art. 12 (3) GDPR, Art. 15 GDPR, Art. 21 GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a sufficient legal basis. The controller also failed to react to the objection of a data subject and only reacted after the data subject filed a complaint with the DPA.

Open original source Links to the regulator's original publication or another source.

Related fines