Skip to content
Enforcement · Italian Data Protection Authority (Garante) NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Meerdere bedrijven: Onvoldoende juridische basis voor gegevensverwerking.

Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante).

Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante).

€18,000 Fine
Multiple Companies
ITALY
Insufficient legal basis for data processing
Art. 5 GDPR Art. 6 GDPR Art. 12 GDPR Art. 13 GDPR
Industrie en Handel.

Full text

De Italiaanse autoriteit voor gegevensbescherming (DPA) heeft drie bedrijven een boete opgelegd, elk van € 6.000. De bedrijven (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. en Zero Due Villa s.s.d.a.r.l.) exploiteren een keten van sportscholen. De bedrijven hebben de telefoonnummers van klanten gebruikt voor direct marketingdoeleinden zonder de toestemming van de betrokkenen. Bovendien hebben de bedrijven niet gereageerd op verzoeken om gegevens te verwijderen, waarmee ze het recht van de betrokkenen op verwijdering negeerden.

GDPR-artikelen: Art. 5 (1) a), b) GDPR, Art. 6 (1) a) GDPR, Art. 12 (1) GDPR, Art. 13 GDPR


Deze inhoud is automatisch vertaald met behulp van machinevertaling. De originele versie is beschikbaar in de brontaal.

How it connects

C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Territorial scope (GDPR) Right to be Forgotten Direct Marketing
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
W256 2227693-1 Austrian FAC: DPA rightly found loyalty program consent for profiling invalid under GDPR On 05.09.2019, the Austrian DPA (DSB) notified the controller of a customer loyalty program that they were initiating an ex officio investigation. The controller responded by… Federal Administrative Court Sep 28, 2023 Marketing Profiling Automated Decision-Making
Ro 2022/04/0026 Austrian VwGH: hotel listings and user reviews on travel platform serve legitimate The data subjects, joint operators of a hotel and restaurant business, ran their establishment through a family business. The controller operates an online travel platform… May 17, 2024 Legitimate Interest Right to be Forgotten Personal Data
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers