The Italian authority sanctions Green Partner for GDPR violations related to non-compliant promotional communications
Facts and context
The Italian data protection authority (GPDP) today published a sanction decision against Green Partner S.r.l.s. (including the imposition of a €15,300 fine) for breaches related to unlawful commercial prospecting, unauthorized processing, and handling of data subject rights requests.
The case originated from a complaint by an individual who received a promotional call and email on behalf of Sorgenia S.p.A., while their number was registered on the Public Opposition Register (RPO).
Grounds for the decision
- Lawfulness of processing obligation (Articles 5, 6 and 7 of the GDPR): The authority found that the promotional call was made without any valid legal basis. The company attempted to justify the contact by a manual misdialing error, but this explanation was deemed unconvincing and contradictory, notably because the company initially denied being the source of the call. Furthermore, the commercial offer sent by email was intended for domestic use, whereas the number the company claimed to contact belonged to a nightclub, which further undermined the credibility of its defense.
- Processor obligations (Article 28 of the GDPR): The authority noted a double violation. On one hand, the company used a subsequent processor (Vanille Service S.r.l.s.) to make the disputed call without the prior written authorization of the controller (Sorgenia). On the other hand, the contractual framework between the controller and the processor was contradictory and outdated, creating confusion about the roles and responsibilities of each, which, according to the authority, demonstrates a failure of the processor to inform and advise the controller regarding potentially non-compliant instructions. The authority relied on the European Data Protection Board (EDPB) Guidelines 07/2020 to recall that the qualification of actors depends on their actual influence over the purposes and essential means of processing.
- Obligations related to the exercise of rights (Articles 12 and 15 to 22 of the GDPR): The company provided an inappropriate response to the complainant's data subject rights request. It stated that it initially considered the request as an attempted fraud, due to an attached compensation claim, and therefore denied any involvement. The authority found this justification unacceptable, considering that the company did not carry out basic verifications that would have allowed it to confirm the authenticity of the request and thus failed in its obligation to facilitate the exercise of the data subject's rights.
Authority's decision
Consequently, the authority imposed a fine of €15,300 on Green Partner S.r.l.s.
Furthermore, the authority ordered the company to adopt adequate measures to ensure that the use of any subsequent processors complies fully with data protection regulations.
Lessons learned
This decision confirms / specifies / recalls that:
- The qualification of controller or processor derives from the factual roles exercised, as recalled by the EDPB Guidelines 07/2020; a contract qualifying the parties as independent controllers does not prevail if, in practice, one acts on the instruction of the other.
- The use of a subsequent processor requires the prior written authorization, specific or general, of the controller and must be governed by a contract imposing the same obligations as those binding the initial processor to the controller.
- A processor has the obligation to inform the controller if an instruction appears to constitute a GDPR violation, including the use of outdated or contradictory contractual documentation.
- A data subject rights request, even if accompanied by a compensation claim, must be treated seriously and cannot be dismissed as fraudulent without reasonable verification of its authenticity.
- The invocation of a "material error" to justify unlawful contact is credible only if supported by evidence and not contradicted by the company's prior statements.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire