ITALY Trends and Developments Contributed by: Paolo Balboni, Luca Bolognini, Davide Baldini and Nicolò Maria Salvi, ICT Legal Consulting
Trends in enforcement Traditionally, the GPDP has been especially concerned with combating unlawful telemar - keting practices, in particular as regards trans - parency and consent requirements, as well as the engagement of third parties (such as call centres) as data processors without the neces - sary data protection safeguards, including the performance of audits by the data controller. In this field, the Garante has issued some of its highest sanctions ever published, such as those against Eni Gas e Luce (issued on 11 December 2019 for a total amount of EUR11,500,000), Tim (issued on 15 January 2020 for a total amount of EUR27,800,000) and Sky Italia (issued on 16 September 2021 for a total amount of EUR3,200,000). More recently, in July 2024, the GPDP ordered Hera (an energy provider) to pay a fine of EUR5,000,000 for violations in the processing of personal data of over 2,300 cus - tomers due to the insufficient implementation of safeguards by Hera’s data processors, which in some cases had led to the activation of energy supply contracts without the knowledge of or consent from the users. During the last few years, the Garante has also focused its attention on the protection of the data privacy rights of children, as apparent from the enforcement actions undertaken against the popular social network TikTok concerning data verification requirements. On 22 January 2021, following the highly publicised death of a ten- year-old girl from Sicily participating in a “black - out” challenge, the GPDP imposed an immedi - ate limitation on the data processing concerning users “whose age could not be established with full certainty so as to ensure compliance with the age-related requirements”. On 3 February 2021 the Italian DPA noted that, following the enforce - ment action, TikTok committed to fulfilling GDPR
Data Protection Enforcement Trends in Italy In general Article 51 GDPR provides that “[e]ach Member State shall provide for one or more independent public authorities to be responsible for monitor - ing the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union”. Under Article 58 GDPR, the supervi - sory authority is granted a wide range of powers, including investigative, corrective, authorising and advisory powers, amongst which – nota - bly – the possibility to levy pecuniary fines and to impose a temporary or definitive ban on the processing of personal data. In Italy, the competent supervisory authority is the Garante per la Protezione dei Dati Personali (so-called Garante or GPDP), whose decisions can be appealed by applying to the ordinary tri - bunal at the second level, and to the Supreme Court of Cassation at the third. The GPDP is widely considered one of the most active and influential supervisory authorities, having issued – as of 31 December 2024 – more than 484 publicly available enforcement actions, amounting to over EUR301,670,797 in sanc - tions. This places Italy second only to Spain in terms of the number of sanctions issued. While the Spanish Supervisory Authority has issued at least 826 sanctions, their total value amounts to approximately EUR97,931,280. The GPDP has applied fines and exercised its corrective pow - ers – such as the imposition of processing bans – across a broad range of GDPR-related mat - ters and industry sectors. Nevertheless, there are certain aspects of the GDPR on which the Authority appears to focus its attention more fre - quently than others.
239 CHAMBERS.COM
Powered by FlippingBook