Fastweb S.p.A.
- Country
- Italy
- Fine
- 4,501,868 EUR
- Date
- 2021-03-25
- Sector
- Telecommunications
- Articles
- Art. 5 par. 1 and 2art. 6 par. 1, 7 and 24art. 25, par. 1art. 24art. 32art. 33 par. 1 andart. 34 of GDPR
Failure to comply with general data processing principles, with the principle of accountability and privacy by design and by default, to report the breach of personal data
The Italian DPA has revealed important "system" criticalities, due to the complex of processing operations carried out by Fastweb regarding both the entire customer database of the Society and the broader range of potential users of the electronic communications sector. In particular, the providers of the Society did not check whether the call centres, with which they collaborated, had properly collected consent for the processing of customers' personal data; at the same time, the Society did not monitor these activities carried out in its interest by the providers. Moreover, the Society used the data coming from the contact lists, provided to it by external partners, without the latter having acquired the users' free, specific and informed consent to the disclosure of their data. Lastly the security measures of the customer management systems were also found to be inadequate and the data breach wasn’t notified neither to the competent DPA nor to the data subjects.
