Illegal call centres

Telemarketing: TIM fined €9.5 million by the Data Protection Authority

The Authority has also established that TIM has systematically failed to comply with its obligations regarding the exercise of data subjects’ rights

La sede di Rozzano (Milano) di Tim. ANSA / MATTEO BAZZI ANSA

2' min read

Translated by AI
Versione italiana

2' min read

Translated by AI
Versione italiana

The Italian Data Protection Authority has fined TIM €9,516,000 for numerous breaches of the regulations governing privacy and telemarketing.

The Authority has turned its attention to the activities of a number of unauthorised call centres which make promotional calls on behalf of the company, using numbers outside the official sales network, in order to unlawfully collect users’ personal data, whilst the users are led to believe they are speaking to an authorised TIM agent.

Loading...

The proceedings stem from complaints about unsolicited marketing calls made on behalf of Tim: around 7,000 in 2025.

The reasons

The Authority explains that the calls were made using numbers not listed in the Register of Communications Operators (ROC) or which had been spoofed, and were often directed at subscribers registered on the Public Opt-out Register (RPO). The Authority deemed the company’s justifications to be insufficient: adherence to a code of conduct – the Authority reiterated – does not exempt the data controller from the obligation to monitor the activities of its partners and to verify the effective application of data protection measures throughout the entire telemarketing supply chain.

The Data Protection Authority has also established that TIM has systematically failed to comply with its obligations regarding the exercise of data subjects’ rights, due to a failure to respond or a delay in responding to requests for access, erasure and objection, as well as the adoption of unduly complex unsubscription procedures which, in some cases, non-functional.
In addition to paying the fine, the company will have to introduce corrective measures to its lead generation procedure, strengthen controls and oversight of its sales network, and bring its procedures for the exercise of data subjects’ rights into line with the regulations.

As regards the agencies’ conduct, the Data Protection Authority explains that its preliminary investigations and inspections have enabled it to uncover the “unlawful scheme through which the agencies were operating, starting with the receipt of unsolicited calls to numbers duly registered with the RPO from telephone operators who, by masking the caller’s number (spoofing), offer to activate TIM offers or services”. This is followed by the sending, via SMS, to the customers concerned of a “hyperlink to a web page belonging to an official partner of the TIM sales network, containing a form which the user is invited to complete in order to submit an independent request to be contacted again (the so-called ‘Lead”) and the subsequent contact with the interested party – based on the (fictitious) request generated via the web – by the call centre, this time using a number duly registered with the ROC, in order to generate an apparently legitimate flow of calls and a formally valid contract process”.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti