Italian Privacy Watchdog Fines TIM €9.5 Million Over Telemarketing and Privacy Violations

Italian Privacy Watchdog Fines TIM €9.5 Million Over Telemarketing and Privacy Violations

By
Key Takeaways
  • TIM Fined €9.516 Million: Italy's data protection authority penalized the telecommunications provider for violations involving unlawful telemarketing, inadequate oversight of third-party partners, and failures to uphold data protection rights.
  • Regulator Uncovered Deceptive Lead-Generation Practices: Investigators found unauthorized call centers used spoofed calls and fabricated "lead" requests to transform unlawfully obtained customer contacts into apparently legitimate sales opportunities within TIM's authorized network.
  • Third-Party Oversight Remains the Controller's Responsibility: The Garante said participation in an industry code of conduct does not absolve a company of its obligation to monitor partners and ensure data protection requirements are followed throughout the telemarketing supply chain.
  • TIM Failed to Adequately Honor Privacy Rights: The authority found the company systematically delayed or failed to respond to requests for access, deletion, and objection, while maintaining overly burdensome procedures for opting out of marketing communications.
  • Corrective Measures Accompany the Fine: In addition to the monetary penalty, TIM must overhaul its lead-generation process, strengthen controls over its sales network, and improve procedures for exercising data subject rights.
Deep Dive

Italy's data protection authority has fined telecommunications provider TIM €9.516 million, concluding that failures in the company's telemarketing operation extended well beyond nuisance calls. According to the regulator, unauthorized call centers funneled unlawfully obtained customer information into TIM's legitimate sales network, exposing weaknesses in the company's oversight of third-party partners and turning illegally obtained contacts into apparently valid customer contracts.

This comes from an investigation sparked by roughly 7,000 complaints and reports filed during 2025, many involving promotional calls made on TIM's behalf from spoofed or unregistered telephone numbers. Numerous calls reached individuals listed on Italy's Public Register of Opposition, the country's do-not-call registry, prompting the Italian Data Protection Authority to examine not only how the calls were placed, but how they ultimately entered TIM's legitimate sales process.

Turning Illegal Calls Into "Legitimate" Leads

As investigators reconstructed the scheme, they found a process designed to obscure where the customer relationship had actually begun. According to the authority, consumers first received unsolicited promotional calls from operators presenting themselves as TIM representatives while disguising the originating number through caller ID spoofing. Those who expressed interest were then sent an SMS linking to a webpage operated by an authorized TIM sales partner, where they were invited to complete a form requesting further contact.

The regulator concluded that the request was anything but independent. Instead, the form created a new "lead" that made it appear the customer, not the earlier unlawful call, had initiated the next step. A call center would then recontact the individual using a telephone number properly registered with Italy's Register of Communications Operators (ROC), allowing the remainder of the sales process to appear compliant even though it rested on an unlawful marketing contact.

TIM argued that its participation in an industry code of conduct demonstrated its commitment to lawful telemarketing. The Garante rejected that argument, saying adherence to a code does not relieve a data controller of its responsibility to supervise partners or verify that data protection safeguards are being applied throughout the telemarketing supply chain. Responsibility for compliance, the authority said, remains with the company acting as the data controller, regardless of how many intermediaries stand between it and the consumer.

The investigation also reached beyond telemarketing practices. The authority found that TIM had systematically failed to meet its obligations when individuals sought access to their personal data, requested its deletion, or objected to further processing. Responses were often delayed or absent, while procedures for withdrawing consent or opting out of marketing communications were unnecessarily complex and, in some cases, ineffective.

Alongside the financial penalty, TIM has been ordered to revise its lead-generation process, strengthen oversight of its sales network, and improve the procedures through which individuals exercise their privacy rights.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong