Legal Updates

Analysis of the Italian ISA Enforcement: Key Lessons from the Eni Gas e Luce Case

FORTSECURE GLOBAL· 2026-08-10🛰 GDPR.eu
#Data Breach#Regulatory Updates#GDPR Compliance#Italy

A major €11.5 million fine against a leading energy provider serves as a critical warning for organizations regarding telemarketing consent and data accuracy.

The Cost of Compliance Failures

In early 2020, the Italian Supervisory Authority (ISA) sent a shockwave through the corporate world by imposing two fines totaling €11.5 million on Eni Gas e Luce (EGL). This enforcement action was the result of a deep dive into the company's marketing practices and customer management systems. At FORTSECURE GLOBAL, we believe this case serves as a landmark example of how systemic failures in data governance can lead to massive financial and reputational damage. The fines were split into two categories: one focusing on illegal data processing in the context of telemarketing, and the other addressing issues with the activation of unsolicited contracts. This dual-pronged enforcement highlights that regulators are looking at the entire lifecycle of customer interaction.

Deep Dive into the Violations

The investigation revealed that EGL had contacted individuals for marketing purposes without obtaining valid consent or, in some cases, despite the individuals being registered on the national 'Do Not Call' registry. Furthermore, the company was found to have systemic issues with data accuracy; contracts were being activated based on incorrect or fabricated data. Under the GDPR, the principle of 'Accuracy' and 'Lawfulness' are foundational. When a company loses control over the quality and source of its data, it loses the legal basis for processing that data. The ISA's decision emphasizes that companies must have robust oversight of their third-party sales agencies, as the data controller remains ultimately responsible for the actions of its processors.

Practical Recommendations for Marketing Compliance

To avoid similar pitfalls, FORTSECURE GLOBAL suggests the following strategic steps: First, implement a centralized Preference Management Center that allows customers to easily view and withdraw their consent for specific marketing channels. Second, perform rigorous due diligence and continuous monitoring of third-party lead generation partners. Third, establish automated data validation checks to ensure that new customer information is verified before being used for contract activation. Finally, integrate the 'Right to Object' into all customer-facing workflows to ensure that opt-out requests are processed across all systems immediately. These steps are essential for maintaining the integrity of marketing databases and ensuring long-term compliance.


แหล่งที่มา: GDPR.eu เผยแพร่ครั้งแรก: Tue, 18 Feb 2020 12:46:53 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: GDPR.eu

เผยแพร่ครั้งแรก: Tue, 18 Feb 2020 12:46:53 +0000

บทความต้นฉบับ: https://gdpr.eu/italy-fines-energy-company-for-multiple-gdpr-violations/

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog