Telecom Italia Fined €9.5 Million for GDPR Violations in Telemarketing Scheme
Italy’s data protection authority, the Garante per la protezione dei dati personali, imposed a €9,516,000 fine on Telecom Italia (TIM) following an investigation that revealed a sophisticated telemarketing scheme. The scheme involved unauthorized call centers using spoofed telephone numbers to contact Italian consumers, including those registered on the national opt-out list. These consumers were then routed through an official TIM partner webpage, creating the illusion of compliant, voluntary callback requests. The Garante clarified that TIM’s reliance on Italy’s GDPR-approved Telemarketing Code of Conduct did not exempt the company from its obligation to monitor and audit its commercial partners actively.
The investigation identified a three-step process used to disguise the initial unauthorized contact. First, call center agents made outbound calls using numbers that were either unregistered or spoofed, masking their true origin. Despite new anti-spoofing regulations introduced by Italy’s communications regulator AGCOM in 2025, thousands of complaints indicated that domestic spoofing calls persisted. Second, consumers were directed to a legitimate TIM partner’s webpage to request a callback, which appeared voluntary. Finally, the callback was made by a registered operator, making the interaction seem compliant and lawful. This process effectively erased the illicit first contact from official records.
The Garante rejected TIM’s defense that adherence to the Telemarketing Code of Conduct was sufficient to ensure compliance. The authority emphasized that signing a code of conduct does not relieve a data controller from the responsibility of continuous and verifiable oversight of its partners’ actions. The ruling highlights a broader enforcement trend in Europe, where regulators focus on actual system behavior and vendor oversight rather than just contractual agreements or written policies.
In addition to the fine, TIM must implement significant reforms, including verifying the lawful origin of every consent request, establishing ongoing monitoring of its sales network, and improving consumer rights procedures to handle access, erasure, and objection requests effectively. The ruling also exposes gaps in Italy’s opt-out register system, which does not protect consumers from calls made using unregistered or spoofed numbers. Consumers affected by unsolicited calls are encouraged to file complaints with the Garante to help enforce data protection laws.