TIM S.p.A.
- Country
- Italy
- Fine
- 27,802,946 EUR
- Date
- 2020-01-15
- Sector
- Telecommunications
- Articles
- Art. 5art. 6art. 7art. 13art. 21art. 24art. 32 andart. 33 of GDPR
Concerns breaches due to (i) unsolicited telemarketing calls; (ii) absence of consent for marketing activities; (iii) invalid consent collected for the use of data controller's apps; (iv) inadequate security measures; (v) mismanagement of data breaches
The key points of this provision are several violations carried out by TIM concerning the consent of the data subjects. First of all, TIM processed data for telemarketing or teleselling purposes without having obtained the consent of the data subjects. Moreover, TIM obtained a consent from data subjects which was not in compliance with the GDPR. With reference to the "TIM Party" program, particularly, it resulted that, in order to subscribe to it, data subjects had to express their consents to receive marketing communications. Additionally, with respect to some TIM apps, it provided only a single flag for the joint acceptance of the "terms of service" and the privacy policy, within which there were references to the processing of data for marketing purposes, geolocation and communication to third parties for their marketing purposes. According to the Italian DPA, the above mentioned processes used to obtain the data subjects’ consent were in contrast with the principles of free expression and specificity provided by art. 4 of GDPR.
