Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
OneDirect Srl: Insufficient legal basis for data processing
How it connects
Related across sources
Guidance EDPB Annual Report 2021 Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Case Law Digital Rights Ireland Ltd v Minister for Communications Case Law VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) Literature Can the GPC standard eliminate consent banners in the EU? Guidance Guidelines 07/2022 on certification as a tool for transfers
Full text
The Italian DPA (Garante) has imposed a fine of EUR 30,000 on OneDirect Srl. A data subject had filed two complaints with the DPA after receiving advertisements by e-mail from the controller, even though he had not consented to it. Even after the data subject had repeatedly objected to the sending, the controller had not stopped the mailings. Moreover, the controller did not respond to the data subject's objections. Furthermore, the controller did not maintain a register of its processing activities and had not sufficiently cooperated with the DPA in the course of the investigation.
Industry: Media, Telecoms and Broadcasting
Original document at the source www.garanteprivacy.it