Fino

Garante per la protezione dei dati personali (Italy) · 12 November 2020

Vodafone Italy S.p.A

About: Accountability, Consent, Data breach, Data principles, Data security, Data subject rights, Unlawful processing

Fine€12,250,601Violation found
Regulator
Garante per la protezione dei dati personali (Italy)
Decided
12 November 2020
Country
Italy
Sector
Not given
Regulator’s reference
9485681
Fino case number
2020/IT/068
Export as PDF

What happened

The Italian DPA (Garante) imposed a fine of €12.25 million on Vodafone Italia S.p.A, following an inquiry into their telemarketing practices which revealed that Vodafone was in violation of several GDPR articles. Vodafone was ordered to implement more appropriate measures to prevent the unauthorized access of customer databases and to ban the further processing of personal data. The Garante initiated the inquiry after multiple complaints from people who received constant unwanted phone-calls from Vodafone telemarketers. Among other things, the inquiry found that Vodafone was using contacts lists purchased from external providers without user consent for telemarketing, and that the security measures implemented by Vodafone to protect their client’s data were inappropriate, as unauthorized parties were calling customers and requesting IDs by pretending to be Vodafone.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Consent
  • Data breach
  • Data principles
  • Data security
  • Data subject rights
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/068.