The Italian authority sanctions FeGi M&A Services for unlawful processing of data for marketing purposes
Facts and context
The Italian data protection authority (Garant for the protection of personal data - GPDP) issued a sanction decision against FeGi M&A Services s.r.l., including a fine of €1,000, for breaches related to telephone commercial prospecting.
The procedure was initiated following a report from a person who received a promotional call from the company, which admitted to having obtained their phone number via an extension module of the Lusha platform on the professional social network LinkedIn.
Grounds for the decision
The authority found two main breaches against the company:
- Lawfulness of processing obligation (Article 5(1)(a) of the GDPR and Article 130 of the Italian Data Protection Code): The company carried out processing for commercial prospecting purposes (approximately 700 phone numbers and 400 email addresses acquired) without an appropriate legal basis. The authority recalls that telephone prospecting is subject to a prior consent regime under Italian legislation transposing the ePrivacy Directive. The authority emphasizes that relying on formal guarantees offered by a third-party data provider (Lusha) does not exempt the controller from their own responsibility under the accountability principle. It was incumbent on them to actively verify the lawfulness of the data source and ensure the existence of valid consent for prospecting by third parties, as well as to consult the public opposition register before launching their campaign. The authority cites its 2013 guidelines on promotional activities and its 2024 code of conduct for telemarketing in this regard.
- Information obligation to data subjects (Article 14 of the GDPR): By collecting personal data indirectly, the company did not provide the data subjects with the information required by the GDPR. The authority specifies that, pursuant to Article 14(3) of the GDPR, this information should have been communicated at the latest at the time of the first communication with the data subject, which was not done in the complainant's case. This breach constitutes a violation of the transparency principle.
Authority's decision
Consequently, the authority imposed a fine of €1,000 on FeGi M&A Services s.r.l.
Furthermore, the authority ordered the prohibition of any further processing of the personal data collected without a valid legal basis as well as their deletion.
Lessons learned
This decision reminds that:
- The accountability principle requires the controller who acquires data from a third party to actively verify the lawfulness of the initial collection and the validity of the legal basis for their reuse, especially for prospecting purposes.
- Relying on contractual guarantees or the reputation of a contact list provider is insufficient and does not constitute a valid defense in case of unlawful processing.
- Electronic prospecting, including by telephone, is subject to specific rules (stemming from the "privacy and electronic communications" directive) that require prior consent, except for strictly regulated exceptions.
- When a controller collects data indirectly, they must provide the information of Article 14 of the GDPR to the data subject at the latest at the time of the first communication with them.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire