Skip to content
Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Rinascente S.p.A.: Non-compliance with general data processing principles

The Italian DPA has fined Rinascente S.p.A.

€300,000 Fine
Rinascente S.p.A.
ITALY
Art. 5 GDPR Art. 12 GDPR Art. 32 GDPR Art. 35 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing loyalty card cancelled and received a new, unsolicited card that contained offensive information about the complainant in her name. The customer complained that their information had been accessed without their consent. During the investigation, the DPA also found that the information on the loyalty card did not specify the retention period of the data for marketing and profiling purposes. In addition, it was not stated that activities were carried out through Facebook-Meta, in which customers' email addresses were forwarded to the American company. As for the e-commerce activities on the website, it was found that, although broad profiling was carried out, Rinascente had not carried out a data protection impact assessment in accordance with the GDPR.

§

In setting the fine, the DPA took into account the high number of data subjects (more than 2,000,000 people were registered in the stores or online), the duration of the violations and the financial performance of the company. GDPR Articles: Art. 5 (1) a), b), c), e), f) GDPR, Art. 12 (1) GDPR, Art. 32 (1) b), d) GDPR, Art. 35 GDPR Industry: Industry and Commerce

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-634/21 OQ v Land Hessen In Case C-634/21, the CJEU addressed a preliminary ruling from the Verwaltungsgericht Wiesbaden concerning OQ's challenge against Land Hessen's refusal to order SCHUFA Holding AG… CJEU ·First Chamber Dec 7, 2023 Profiling Automated Decision-Making Marketing
HvJ EU 9 januari 2025, C‑394/23 (Mousse) Artikelen: 5(1)(c), 6(1), en 21 AVG Onderwerp : Beginsel van minimale gegevensverwerking Gek genoeg verwijst het HvJ EU zelf niet naar HvJ EU 1 augustus 2022, C‑184/20… HvJ EU 9 januari 2025, C‑394/23 (Mousse). ·CJEU Jan 9, 2025 IP Address Retention Period Identification
2025 Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the… EDPB Oct 13, 2025 IP Address Data Portability Direct Marketing
W274 2320278-1 Austrian Federal Administrative Court: address publisher's data transfer and Article 15 An address publishing service and direct marketing company (the controller) sent the address data of a data subject to clients as part of its business activities. The clients are… Sep 14, 2026 Personal Data Right to Restriction Retention Period