Garante · 556/2026
Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A.
Holding
The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice. It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached Article 5(2) GDPR by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed Article 24 GDPR and Article 28 GDPR. The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain. Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of Article 5(1) GDPR, Article 6 GDPR, Article 7 GDPR and Article 130 of the Italian Data Protection Code. The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed Article 25 GDPR. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed Article 32 GDPR. Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed Article 12(2) GDPR, Article 24 GDPR and the rights of the data subjects. It further found an infringement of Article 12(3) GDPR in relation to requests that were not answered or were answered with unjustified delay. The DPA ordered the controller to amend its procedures for generating Leads and callbacks and to ensure that consent to be contacted could be shown to originate from the actual holder of the number. It also ordered the controller to strengthen its supervision of commercial partners and improve its procedures for handling the exercise of data subject rights. Finally, the DPA imposed a fine of €9,516,000 on the controller. It took into account as a mitigating factor the controller’s adherence to the Code of Conduct for telemarketing.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
Full text 7 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
SEE ALSO Press Release of July 31, 2026 [Web Doc. No. 10277005] Decision of July 23, 2026 Register of Decisions No. 556 of July 23, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003, hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”); HAVING REGARD TO the documentation on file; HAVING REGARD TO the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801); RAPPORTEUR: Prof. Pasquale Stanzione;
FACTS AND PRELIMINARY INVESTIGATION CONDUCTED
Origin of the preliminary investigation The Authority, in exercising the powers set forth in Articles 157 and 158 of the Code, initiated an inspection of TIM S.p.A. (hereinafter “TIM,” the “Company” or the “Data Controller”), in collaboration with the Special Unit for Privacy Protection and Technological Fraud of the Guardia di Finanza, following the receipt of numerous complaints and reports, including those submitted by a correspondent for a well-known television program. In a nutshell, the reports highlighted a phenomenon already known to the Authority, characterized by the activities of fraudulent call centers that make promotional calls on behalf of TIM using phone numbers outside the Company’s official sales network. This conduct is aimed at the unlawful collection of users’ personal data; users, under the mistaken belief that they are speaking with an authorized TIM agent, provide this information and sometimes sign up for promotional offers. Specifically, among the operational schemes recently implemented by these agencies and reported by complainants is the following: a) Receipt of unsolicited calls on phone numbers duly registered with the Public Do Not Call Registry (hereinafter “RPO”) from telephone operators who, using caller ID spoofing techniques, propose the activation of TIM offers or services; b) sending data subjects, via SMS, a hyperlink to a webpage of an official partner in the TIM sales network, containing a form that the User is invited to fill out to submit an independent request for a callback (a so-called “Lead”); c) subsequent contact with the data subject—based on the (fictitious) request generated via the web—by the call center, this time using a phone number duly registered in the Register of Communications Operators (hereinafter “ROC”), in order to generate an apparently legitimate flow of calls and a formally compliant contract formation process.
Preliminary Investigation Conducted Based on the information provided in the reports, and in parallel with the investigations conducted in relation to other reports and complaints, the Office requested that TIM provide information necessary to obtain a complete picture of the various critical issues identified by the reporters and complainants. Through the inspection and preliminary investigation conducted regarding the Company, it was possible to obtain a significant amount of information and documents, which were made available to the Authority by the Guardia di Finanza via letters dated March 26 and 27, 2025, Ref. No. 442/25, and subsequently supplemented by notes Ref. No. 54010 dated April 18, 2025, Ref. No. 55188 dated April 23, 2025, Ref. No. 95514 dated July 7, 2025, Ref. No. 108311 dated August 4, 2025, and, most recently, Ref. No. 174524 dated December 16, 2025.
INITIATION OF PROCEEDINGS FOR THE ADOPTION
OF CORRECTIVE AND PENALTY MEASURES
Findings of the Preliminary Investigation and Initiation of Proceedings Based on the evidence gathered during the activities described above, by a notice dated February 9, 2026 (Ref. No. 18734), served in accordance with Article 166, paragraph 5, of the Code and reproduced in full herein, the Office initiated proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation against the controller, inviting the latter to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). The alleged violations are detailed below.
Verification procedures regarding lead forms collected by digital agencies or on the TIM website—ex officio finding During the inspection, initiated ex officio against TIM, certain critical issues emerged regarding the procedures for acquiring personal data (so-called “leads”) collected through partner digital agencies or directly from the Data Controller’s website. In particular, there was a complete lack of mechanisms to verify the actual ownership of the phone numbers provided in the online data collection forms, thereby exposing data subjects to the risk of unsolicited contact. In order to remedy the irregularities identified and in accordance with the principle of accountability (pursuant to Article 5, para 2, of the Regulation), during the course of the investigation—through submissions filed in the months following the inspection— the Company stated that it had implemented an automated preventive verification system, based on an M2M integration with the central TIMCO system. Specifically, the new procedural framework is based on an opt-out mechanism via SMS: upon entry of the lead, the data subject receives a notification message and has a 5-minute window to deny ownership of the contact information or revoke consent (the so-called “right to change one’s mind”). TIM has also adopted additional technical and organizational measures to protect data subjects, including: (i) anti-phishing measures: implementation of communications sent exclusively via certified aliases and transparent URLs that can be uniquely traced back to the Data Controller’s official domain; and (ii) anti-fraud systems (IP control): the introduction of an automated blocking system designed to prevent the submission of multiple requests from the same IP address within a 15-minute time interval, specifically aimed at neutralizing and countering the mass upload of personal data via computer applications (so-called “bots”). With regard to the system’s operational effectiveness and the progress of the aforementioned infrastructure, the Data Controller submitted additional documentation (Ref. No. 174524 dated December 16, 2025) certifying that the system had undergone final testing, with the full and final rollout scheduled for January 31, 2026. While the Office views the Data Controller’s efforts to comply favorably, it has nevertheless notified the Company of an alleged violation of Article 25, para 1, of the Regulation, for failing to adopt adequate technical and organizational measures to ensure, from the design stage onward (“Data Protection by Design”), that processing was carried out in accordance with the principles of the legislation at every stage. With specific regard to the aforementioned opt-out measure, the Office deemed it structurally unsuitable for protecting individuals whose phone numbers are entered into forms without their knowledge. In fact, these individuals receive an unsolicited text message containing an invitation to click a link to block future contacts; in this context, a procedure requiring prior confirmation of consent to be contacted again (opt-in) appears to be more appropriate. During the year 2025, the Authority received numerous reports and complaints (approximately 7,000 complaints) concerning the receipt of unsolicited and unauthorized promotional communications on behalf of TIM. Some of these reports, which were initially the subject of separate investigations, were subsequently consolidated into a single main proceeding for the purpose of unified handling, given the evident systemic and structural nature of the alleged conduct. A first and substantial group of complaints relates directly to TIM’s overall management of its data assets. The inspection and the findings of the preliminary investigation revealed that the Company, despite having made efforts and invested financial and organizational resources to combat the phenomenon of so-called “unknown calls,” it implemented control systems across the entire data collection “chain” that proved to be entirely unsuitable and deficient in many respects. In particular, the investigations revealed that TIM had engaged third parties to process personal data without conducting the necessary preliminary checks to ensure compliance with the safeguards required by the GDPR, and without adopting adequate organizational measures to constantly monitor compliance with data protection regulations by its sales network. The preliminary investigation made it possible to obtain documentary evidence (including screenshots extracted from the company’s systems) proving that commercial activation orders were entered into the company’s databases following unlawful telephone contacts. These abusive promotional calls originated from numbers not registered with the ROC and were directed, in many cases, at subscribers duly registered with the RPO. The unlawful conduct can be attributed to official TIM business partners, specifically the sales agencies XX, XX, XX, and XX. The modus operandi adopted by these partners involved initiating sales processes through preliminary telephone contacts made without any consent whatsoever and using untraceable or altered (spoofed) phone numbers. Subsequently, in order to artificially mask the unlawful origin of the contact, the partners asked the data subjects to click on a specific link received via SMS or messaging services. This operation was designed to generate a fictitious, independent request for follow-up contact (lead), intended to “clean up” the data trail vis-à-vis the parent company. Consequently, the partners reported to TIM that they had acted in response to a spontaneous request from the User through regular channels, concealing the actual and abusive telemarketing activity carried out beforehand. a) Review of Individual Investigation Files In order to outline the objective scope of the violations identified, the findings regarding the individual files examined by this Authority are set forth below; these findings confirm the ineffectiveness of the Company’s compliance controls. - File No. 425095: During the inspection, it emerged that certain orders in the name of the data subject, entered into the company’s systems by TIM’s partner XX, were listed as resulting from spontaneous online requests for follow-up contact regarding leads and subsequent regular phone calls. The investigation revealed a completely different reality: the contacts did not stem from the User’s initiative but represented the final stage of repeated and persistent abusive promotional calls originating from unregistered numbers (including WhatsApp accounts improperly bearing the Company’s logo). TIM’s preventive control and ex-post monitoring systems proved inadequate, as they recognized only the “cleaned-up” calls that occurred after the generation of the fictitious leads as valid, ignoring the entire preceding unlawful phase. The structural inadequacy of the controls is confirmed by the fact that, despite hundreds of thousands of contacts, the Company detected only minor discrepancies without ever reporting any major issues involving the agency in question. - Cases Nos. 496215 and 437668: The complainant filed a complaint with the Public Prosecutor’s Office, alleging that he had received automated calls on behalf of TIM and that leads were generated via links sent through WhatsApp. Following the complaint, the Data Protection Authority sent a request for information to TIM. The case files confirmed that multiple unlawful contacts had been made to promote TIM services using spoofed phone numbers by agencies within the company’s sales network. Specifically, the violations were attributed to the actions of XX in connection with an activation order (file no. 496215) and to the actions of XX (file no. 437668). In this case as well, the company’s information systems architecture processed the contracts without detecting the illegality of the upstream data processing. - File No. 434470: On February 18, 2025, the complainant, acting on behalf of third parties, reported automated calls to a subscriber registered with the RPO on behalf of TIM, originating from numbers not registered with the ROC. During the inspection, evidence was obtained regarding an activation order entered into TIM’s information systems by the business partner XX. The documentation on file unequivocally confirmed that the subscription to the service originated from abusive commercial contacts carried out using CLI spoofing techniques, thereby circumventing the Company’s Tracking and verification systems. - Case No. 444902: The complainant reported, on behalf of a third party, an automated call received on January 23, 2025, on a number duly registered with the RPO to promote TIM services. Following an initial expression of interest, the data subject was contacted again by a self-proclaimed consultant via a WhatsApp profile bearing the TIM logo to provide contract details. To complete the subscription, the data subject was asked to click on a link received via SMS from another untraceable number. This link led to a web page where data was entered to artificially generate an independent request for a callback (Lead). The investigation revealed an activation order processed and entered by TIM’s official partner XX. In the system, the transaction appeared legitimate and resulted from a “Lead” associated with the data subject’s account. The actual facts, however, contradicted the findings of TIM’s management portal: the contact did not stem from a spontaneous request by the customer, but was the result of multiple unauthorized contacts that occurred on the same day and an SMS containing the link to generate the false request. A particularly serious issue emerged in the fact that Partner XX had already been subject to Level II audits by TIM in November 2023, which had concluded with a rating of “INADEQUATE.” Extremely serious violations had been identified, such as the processing of data by an unauthorized subcontractor and the use of real leads in a test environment. Nevertheless, TIM had limited itself to issuing a formal warning and implementing a paper-based monitoring system that proved to be completely ineffective. - File No. 513320: In this case as well, the order was entered into TIM’s official systems by a TIM partner, XX., confirming the vulnerability of the Company’s acquisition channels to data flows of illicit origin. Upon discovering the unlawful processing of her data through unauthorized channels, the complainant subsequently requested that TIM cancel the order and the contract, as well as identify the partner responsible for the calls. Following the Data Protection Authority’s request for an investigation (October 3, 2025), TIM responded to the complainant on October 22, 2025, and to the Authority on October 23, 2025. - File No. 518841: In a complaint filed on September 9, 2025, the complainant alleged that he had been deceived by an individual who falsely claimed to be an agent of the competitor “XX,” who fraudulently induced him to switch to TIM by providing false technical information. The case files provided further evidence that personal data unlawfully obtained from unidentified third parties acting on behalf of the Company had been entered into TIM’s information systems via activation orders. The complainant expressed concern that unidentified individuals had obtained all of his personal and sensitive data (including his address), creating a high risk of retaliation and further unlawful use of such data. - Case No. 557370: The complainant reported receiving unsolicited promotional emails, noting that he had refused to give consent for marketing purposes from the time the contract was signed and on every subsequent occasion. The documentation included in the case file revealed that TIM had sent promotional communications to the data subject without prior and valid consent. b) Analysis of Aggregated Data and Obvious Discrepancies The structural inadequacy of the compliance and monitoring system established by TIM emerged unequivocally from the statistical analysis and the cross-referencing of log files with the monthly activation volumes provided by the Company itself, with particular reference to the month of November 2024. Operational data relating to sales agencies reveal glaring inconsistencies that should have prompted the Company to immediately block the data flows and trigger security alerts: Sales Partner Declared Leads Contacts Made Volume Discrepancy Conversion Rate / Outcome XX 17,388 22,242 +4,854 contacts compared to leads Contract activation rate