Iliad Italia S.p.A.
- Country
- Italy
- Fine
- 800,000 EUR
- Date
- 2020-07-09
- Sector
- Telecommunications
- Articles
- Art. 5, par. 1, lett. a) and f)art. 32 of GDPR
This fine concerns breaches due to (i) failure to comply with the lawfulness, fairness and transparency principle; (ii)insufficient security measures applied to the storage of traffic data.
Since the end of 2018, the Italian DPA has received a number of complaints and reports concerning the processing of customer data for the activation of sim cards, the processing of data for promotional purposes and the measures adopted for the storage of data in the customers' personal area.<br />In particular, the Society imposed to the consumers the contextual acceptance of the contractual conditions and the privacy policy, and it requested the consent for promotional purposes, specifically mentioned in the privacy policy, without such processing existing or being envisaged.<br />Moreover, in the activation of a new sim through physical channels, the Society has set up special machines called 'Simbox', which did not respect the confidentiality of potential customers in the activation's process of such sim.<br />Finally, the company did not comply with the Italian privacy law that requires the providers of electronic communication services to use, pursuant to Article 32 of the Regulation, specific technical and organisational measures appropriate to the existing risk.
Reported by: RPLegal&Tax Associazione Professionale
