Enforcement · Italian Data Protection Authority (Garante) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Interflora Italia S.p.A.: Insufficient legal basis for data processing
How it connects
Related across sources
Guidance EDPB Annual Report 2021 Case Law Google LLC v CNIL Case Law Google Spain SL and Google Inc. v AEPD and Mario Costeja González Case Law CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Literature Can the GPC standard eliminate consent banners in the EU? Case Law HvJ EU 9 januari 2025, C‑394/23 (Mousse).
Full text
The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a sufficient legal basis. The controller also failed to react to the objection of a data subject and only reacted after the data subject filed a complaint with the DPA.
Industry: Industry and Commerce
Original document at the source www.gpdp.it