The Italian authority sanctions TIM S.p.A. for serious data protection breaches in telemarketing
Facts and context
The case originated from an inspection initiated by the authority, notably following numerous complaints and reports denouncing unsolicited promotional calls made on behalf of TIM by unofficial call centers.
These centers used caller ID spoofing techniques to contact individuals, including those registered in the Public Opposition Register (RPO), to offer TIM services. To conceal the illicit origin of the contact, operators encouraged interested persons to click on a link received by message, thus generating a supposedly spontaneous callback request ("lead"), which was then processed by TIM's official sales network as a legitimate approach.
Grounds for the decision
- Data protection by design obligation (Article 25 of the GDPR): The authority found that the online forms of TIM and its partners for lead collection contained no mechanism to verify the actual ownership of the provided phone numbers. The opt-out confirmation system by text message, implemented during the procedure, was deemed inadequate as it reverses the logic of consent by requiring an action from the data subject to refuse unsolicited processing, violating recital 32 of the GDPR. The authority considered that a preventive opt-in confirmation procedure was necessary to ensure compliance.
- Lawfulness of processing obligation (Articles 5, 6 and 7 of the GDPR): The authority judged that promotional contacts were made without a valid legal basis. TIM's partners made an initial unlawful contact, then encouraged the person to click on a link to generate a supposedly spontaneous callback request. The authority considered that this subsequent consent could not "cleanse" the illegality of the initial contact, as processing began from the first unauthorized interaction.
- Accountability obligation of the controller (Article 5, paragraph 2, 24 and 28 of the GDPR): The authority rejected TIM's argument that breaches originated from uncontrollable third parties. It found fault in the selection ("culpa in eligendo") and supervision ("culpa in vigilando") of its partners. The blatant statistical anomalies (number of contacts far exceeding declared leads, extremely low conversion rates) should have alerted TIM and triggered controls, demonstrating a failure in its monitoring obligations over the entire processing chain. Membership in a code of conduct, while a mitigating factor, does not exempt the controller from demonstrating the concrete effectiveness of its measures, as recalled by the European Data Protection Board (EDPB) guidelines 1/2019.
- Security of processing obligation (Article 32 of the GDPR): Security measures of the consent collection systems and order processing were deemed insufficient. The IT architecture allowed the integration of data of illicit origin, without effective blocking or alert mechanisms against manifestly abnormal data flows.
- Obligation to respect data subjects' rights (Article 12 and Articles 15 to 22 of the GDPR): The authority found systemic breaches in handling rights exercise requests, including significant delays (up to 120 days), incomplete responses or lack of response. Moreover, consent withdrawal procedures were deemed excessively complex (requiring authentication on a client area), violating the principle that withdrawal must be as easy as giving consent (Article 7, paragraph 3, of the GDPR).
Authority's decision
Consequently, the authority imposed a fine of €9,516,000 on TIM S.p.A.
Furthermore, the authority ordered TIM S.p.A. to bring its lead collection procedures into compliance by implementing a mechanism to verify the identity of the person, to strengthen control and monitoring measures of its business partners, and to adapt its processes to ensure a prompt and effective response to rights exercise requests.
Lessons learned
This decision reminds that:
- Consent obtained after an initial unlawful contact cannot "regularize" the entire processing chain retroactively, as the violation is consummated from the first unauthorized operation.
- The controller has an active monitoring obligation ("culpa in vigilando") over the entire subcontractor chain, which cannot be limited to formal or documentary control.
- Manifest statistical anomalies (e.g., a volume of contacts far exceeding the number of generated leads) constitute indicators of non-compliance that must trigger thorough audits.
- An opt-out confirmation mechanism to verify a contact request is insufficient; data protection by design requires a double opt-in confirmation system to ensure the real will of the line owner.
- Membership in a code of conduct does not constitute an irrebuttable presumption of compliance and does not exempt the controller from its obligation to demonstrate the concrete effectiveness of its measures.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire