Garante per la protezione dei dati personali (Italy) - 312/2026

From GDPRhub
Garante per la protezione dei dati personali - Case number: 312/2026

Internal number: 10255198

Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5 GDPR
Article 6 GDPR
Article 7 GDPR
Article 12 GDPR
Article 15 GDPR
Article 24 GDPR
Article 28 GDPR
Art. 130 of the Code
Type: Complaint
Outcome: Upheld
Started: 10.03.2026
Decided: 29.04.2026
Published: 02.06.2026
Fine: 15,000 EUR
Parties: Nuova Corrente S.r.l.
Joseph Agency S.r.l.s
National Case Number/Name: Case number: 312/2026

Internal number: 10255198

European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: ap

The DPA fined a utilities company €15,000 for not being able to explain where (and on what legal basis) it obtained personal data processed for marketing purposes. In addition, the controller failed to adequately respond to a data subject’s access request.

English Summary

Facts

Nuova Corrente S.r.l. (the controller) is a utilities company. A data subject filed a complaint with the DPA, on the grounds that they had received several direct marketing calls on behalf of the controller. According to the data subject, their data was processed for fraudulent purposes, as they were not aware that they were entering into a contract until the second call. The controller had also not responded adequately to the data subject’s access request under Article 15 GDPR.

The controller responded to the access request during the DPA’s investigations. The controller explained that the data subject’s data had been processed by a separate company (Joseph Agency S.r.l.s, the processor) hired by the controller to carry out promotional activities.

The controller claimed that the data was processed based on the data subject’s consent. The controller also argued it was not involved in any potential fraudulent conduct carried out on its behalf. The controller stated it assessed and terminated its contract with the processor in order to prevent similar situations in the future. Finally, the controller argued that it did not obtain most of its contact data from its processor.

Holding

The DPA found a violation of Articles 5, 6, and 7 GDPR, as well as Article 130 of the Code. According to the DPA, the controller provided contradictory statements on how it obtained the data subject’s personal data. The controller named several companies as its source of the data subject’s data at different points of the investigation. The DPA also found issues with the way the one of the companies obtained consent, as it allowed for the data to be transferred indiscriminately regardless of the data subject’s choices.

The DPA also found a violation of Articles 24 and 28 GDPR. The DPA noted that the controller had not fulfilled its obligations arising from the principle of accountability, especially in explaining where the data subject’s data was obtained from or demonstrating that the data was processed lawfully. The DPA noted that the controller seemed to have completely delegated decisions on how to obtain personal data for direct marketing to its processor.

Finally, the DPA found a violation of Articles 12 and 15 GDPR, as the controller had not adequately responded to the data subject’s access request. The DPA found that the controller lacked appropriate measures to handle data subjects’ requests to exercise their rights in general.

The DPA fined the controller €15,000. The DPA considered it a serious violation, as it affected at least nine other data subjects.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

[web doc. no. 10255198]

Provision of April 29, 2026

Register of Provisions
No. 312 of April 29, 2026

THE ITALIAN DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;

CONSIDERING Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter "Regulation");

HAVING SEEN the Personal Data Protection Code (Legislative Decree No. 196 of June 30, 2003), as amended by Legislative Decree No. 101 of August 10, 2018, containing provisions for the adaptation of national legislation to the aforementioned Regulation (hereinafter the "Code");

HAVING SEEN the documentation in the file;

HAVING SEEN the observations formulated by the Secretary General pursuant to Article 15 of the Guarantor's Regulation No. 1/2000, adopted by resolution of June 28, 2000;

RAPPORTEUR: Professor Pasquale Stanzione;

1. INVESTIGATIVE ACTIVITY

1.1. Introduction

With deed no. 36361 of March 10, 2026, notified on the same date by certified email, which is reproduced here in its entirety, the Office initiated, pursuant to Article 166, paragraph 5, of the Code, a proceeding for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation against Nuova Corrente S.r.l. (hereinafter "Nuova Corrente" or the "Company"), represented by its legal representative pro tempore, with registered office in Vibo Valentia (VV), Via Spogliatore, s.n.c., VAT no. 12126890966.

The proceeding stems from an investigation initiated by the Authority following the receipt of a complaint in which the interested party complained of having received two promotional and fraudulent calls made in the interest of Nuova Corrente and of the inadequate response to the request submitted pursuant to Article 166, paragraph 5, of the Code. 15 of the Regulation. In this case, the interested party stated that the first contact had been made by an external company claiming to be the local distributor and feared a double billing error, warning that the interested party would be contacted again by a company called "Nuova Corrente." The second contact had been made by a Nuova Corrente operator and was aimed at concluding a new supply contract. Therefore, the interested party contacted the Authority to obtain the protections recognized by the applicable legislation on the protection of personal data.

1.2. Requests for information made by the Authority

Having examined the complaint and all the attached documentation, with a note dated October 13, 2025 (see Prot. No. 135446/25), the Office invited Nuova Corrente, pursuant to art. 157 of the Code, to provide its observations regarding the content of the complaint.

Subsequently, with a note dated November 3, 2025 (see Prot. No. 145522/25), the Company first responded to the interested party's original request for access, clarifying in particular that the complainant's personal data had "been acquired under an agency contract stipulated with the company JOSEPH AGENCY S.R.L.S. (…), duly registered in the Register of Communications Operators (…). This company had been entrusted (…) with carrying out promotional and customer acquisition activities, with specific contractual obligations regarding the protection of personal data. In turn, Joseph Agency S.r.l.s. acquired Ms. Ferrario's contact information from the company Clean Energy Consulting, which collected the data via the web portal https://offertegratis.com/informativaPrivacy."

On the same occasion, Nuova Corrente also stated that only personal and contact information had been processed for promotional purposes and on the basis of the consent granted by the interested party "as shown in the electronic registration record (...), dated July 18, 2025, at 2:18:04 PM, from address XX (...) following consultation of the privacy policy on the website https://offertegratis.com/informativaPrivacy."

Nuova Corrente acknowledged the process described by the complainant—who had received an initial call from Joseph Agency S.r.l.s. and a second from an internal Nuova Corrente operator to finalize the contract—and produced the recording of the second call, noting that "Listening to the recording unequivocally reveals the courtesy and professionalism demonstrated by the Nuova Corrente operator. Having noted the user's discomfort and acknowledged his disappointment at not having received any information and his refusal to receive it, she concluded the conversation by thanking Ms. Liliana with a 'thank you very much.'"

Finally, the Company documented that "In a spirit of full accountability (Article 5, paragraph 2, and Article 24 GDPR), and following an internal assessment, Nuova Corrente S.r.l. deemed the performance and operating methods of the aforementioned agency to be unsatisfactory. Therefore, on July 31, 2025, the undersigned formally notified Joseph Agency S.r.l.s. The immediate termination of the agency mandate, as a corrective measure aimed at preventing the recurrence of similar situations and ensuring a higher standard of protection for data subjects.

In a note dated November 10, 2025 (see Prot. No. 149791 of November 12, 2025), the interested party submitted its observations, highlighting that the Company had responded to the request for access only following the request notified by the Authority and that "the aforementioned online service where the data would have been entered was never used, neither on the date indicated nor on any other date, and the dynamics appear highly unlikely, given that it is a Bulgarian-Canadian website."

In the note in question, the interested party also highlighted that "the data was not used for legitimate purposes, i.e., a commercial proposal, but rather to organize a potential fraud. In fact, the company contacted the number they had to report an administrative and technical anomaly in their area, without actually communicating that a contract was being signed. It should be noted that this circumstance clearly emerges from the audio recording filed by the professional himself during his counter-arguments and that "as soon as he learned of the unlawful processing of his data, namely during the aforementioned voice recording, the professional should have acted immediately to verify the proper processing, whereas no action appears to have been taken up to the date of the complaint to the Guarantor."

Subsequently, following access by the Office to the offertegratis.com website, which is attributable to the Bulgarian company Clean Energy Consulting, it emerged that:

- the portal is not navigable in any way, but only contains a form for collecting personal data (i.e., name, surname, telephone number, email address) and user consent ("I have read and accept the information"; "I consent to the processing of my personal data for the sending, by offertegratis.com, of promotional communications relating to the products and/or services of offertegratis.com or its affiliated companies, using the telephone with an operator and/or also through automated systems (e.g., email, SMS)"; "I consent to the transfer for marketing and commercial purposes, using the telephone with an operator and/or automated systems (e.g., email, SMS) and/or sending promotional material by post, to third parties belonging to different economic categories or "I consent to the transfer for marketing and commercial purposes, through the use of telephone with an operator and/or automated systems (e.g., email, text message) and/or the sending of promotional material by post, to third parties belonging to the following economic or product categories: Tourism, Leisure, High Tech, Fashion, Furniture, Consumer Goods, Food & Beverage, Finance, Banking, Insurance, Energy, Environment, Communications, Media, Entertainment, Real Estate, Pharmaceuticals, Automotive, Clothing and Textiles, Training, Energy, Publishing, ICT, Retail, Sports, Telecommunications, and Services in general. Transfer Information"); however, the formulas used to obtain the second and third consents appeared to overlap;

- clicking on the "Click here to manage them" link opened a second banner allowing users to provide differentiated consent by product sector, and at the bottom of each sector was the link "Here you can view the complete list," which allowed users to consult the same "Transfer Notice" where numerous owners and an equally numerous product categories were listed;

- clicking on the "Transfer Notice" link redirected the user to the same notice referred to in the previous point.

Therefore, in light of the findings and documentation provided, as well as the findings made by the Office, it was appropriate to conduct a further investigation, sending the Company a request for additional information pursuant to and for the purposes of Articles 58, paragraph 1, letter a) of the Regulation and 157 of the Code (see Protocol No. 178264 of December 23, 2025).

In a note dated January 12, 2026 (see Prot. no. 3405 of January 13, 2026), Nuova Corrente preliminarily stated that it had acquired from JOSEPH AGENCY S.R.L.S. a total of ten personal data records, which "according to the partner's declaration, come from lists in its possession, acquired from qualified third-party suppliers who have certified the lawfulness of the collection and the existence of a suitable legal basis for the promotional contact."

Nuova Corrente also clarified that the telemarketing and teleselling activities carried out on its behalf were "conducted via direct telephone contact. The operational flow includes: presentation of the offer, explanation of the financial terms, obtaining consent, transmission of the contractual proposal, and subsequent contract validation by Nuova Corrente S.r.l."

Regarding the parties involved in carrying out the aforementioned activities, the Company stated that "Nuova Corrente S.r.l. acts as Data Controller for the contract validation and customer management phases. JOSEPH AGENCY S.R.L.S. has been formally appointed as Data Processor (pursuant to Article 28 of the GDPR) for telephone contact and promotional activities. The actual contact operators act as authorized persons under the direct responsibility of the Data Processor."

Regarding the selection of list providers, Nuova Corrente clarified that this activity "is delegated to the Data Processor, who has the contractual obligation to select compliant suppliers and obtain certifications of lawfulness."

Nuova Corrente further stated that it had provided binding written instructions through the deed of appointment as Data Processor and contractually provided for random checks on call quality and periodic document checks to ensure process compliance. Furthermore, "The Data Processor declared that it would carry out preliminary consistency and traceability checks, including verification of consent and cross-checking with the Public Register of Opposition (RPO). Nuova Corrente S.r.l. conducts random and second-level checks in the event of reports or anomalies."

Regarding the remedial measures adopted in the event of illicit contacts, the Company stated that it would adopt "immediate corrective measures: suspension of the registry, request for urgent clarification from the partner, and, in the most serious cases, termination of the relationship," reiterating that the mandate granted to JOSEPH AGENCY S.r.l.s. had expired on July 31, 2025, due to performance and operating procedures deemed unsatisfactory.

Finally, Nuova Corrente stated that it had "an internal procedure that provides for the receipt, recording, and involvement of the Data Controller to provide feedback to the data subject within the legal deadlines" and requested a brief extension of the originally granted deadline to acquire the documentation held by JOSEPH AGENCY S.r.l.s. This extension was granted with note Prot. No. 5294 of January 15, 2026.

Thus, in a further response sent on January 27, 2026 (see Prot. No. 11635 of January 28, 2026), the Company preliminarily noted that "During the period under investigation, the data flow managed through the commercial partner Joseph Agency S.r.l.s. was extremely limited, limited to a total of 10 records. These contacts did not result from bulk purchases of "cold" lists, but rather from targeted digital lead generation activities. As evidenced by the attached tax documentation (Meta Platforms Ireland Ltd. invoices), the acquisition occurred through advertising campaigns on social media platforms (Facebook/Instagram), managed by the partner in compliance with applicable advertising policies.

The Company also stated that "Nuova Corrente S.r.l.'s promotional activity is strictly subject to prior consent verification. Telephone contact with users occurs exclusively following the receipt of a qualified lead, accompanied by technical logs (IP and timestamp). During the call, the operator verifies the caller's identity and renews the information, proceeding with the commercial proposal only if there is a clear expression of interest."

Regarding the assignment of the mandate to Joseph Agency S.r.l.s., Nuova Corrente specified that the choice "was not random, but based on criteria of formal and substantial reliability. The partner is an Italian corporation duly registered in the Register of Communications Operators (...). This registration constitutes, for the Data Controller, a qualified indicator of professionalism and compliance with industry regulations.

Regarding the documentary evidence regarding the source of the complainant's data, Nuova Corrente stated that "The technical evidence in our possession, consisting of registration metadata and proof of advertising investments made by the partner on the Meta platform (...), unequivocally confirms that the data was generated in a lawful and tracked acquisition context, as documented in the attachment entitled "free lead generation contacts." Further confirming the authenticity of the collection, a thorough analysis of the web traffic logs revealed a crucial element: the complainant's consent was given on two separate occasions. In addition to the first tracking, a second expression of consent was found directly through the Facebook platform. This circumstance, certified by the system logs, rules out the possibility of involuntary or automated input, confirming the user's genuine interest in the commercial proposal."

Furthermore, in light of the complainant's allegations, the Company requested "to arrange, as part of this investigation, a technical assessment to verify whether the address XX can actually be traced back to the complainant's user account or internet connection."

In a note dated January 30, 2026 (see Prot. No. 14184 of February 2, 2026), the complainant noted that "no reason is provided either for the failure to respond to the initial request for access to her data, or for the fact that the data was used for purposes bordering on fraud, given that the personal data was used to report a technical fault/anomaly in the area and not, as in reality, for a commercial offer. Both of these matters, also frankly admitted by the opposing party, are reflected in the audio recording already filed by them."

Furthermore, regarding the origin of the personal data, the interested party highlighted that "1) the counterparty's documentation does not in any way reveal a univocal correspondence between the use of this IP and the declaration of consent to the use of the data; 2) the fact that a data acquisition invoice was paid to Meta does not guarantee that the data was acquired lawfully nor that the invoice concerns one's personal data and/or that of other potential customers; 3) (...) it is at least controversial that in the previous counter-argument Nuova Corrente srl had declared that the data had been acquired by the Bulgarian company Clean Energy Consulting via the offertegratis.com platform (a website registered in Canada), while in this case the data would have been acquired via Facebook by Meta, based in Dublin, a sign that evidently there is no certainty as to the origin of the data; 4) It can, however, be ruled out that the data was acquired through these platforms. In fact, the call center operator, upon the first call, had not only the personal and contact details, but also the POD and PDR codes for the supply and even the bank IBAN—information that is normally acquired exclusively through data breaches of other electricity and gas suppliers. This is because online comparison platforms do not require either the POD, PDR, or bank IBAN, which are acquired directly from the supplier only during the contract signing phase. Furthermore, "in the first counter-argument (...), the electronic trace would report the date of 07/18/2025 (...). In the second counter-arguments, Nuova Corrente srl, however, states that consent from the disputed IP address would have occurred on 07/04/2025."

The complainant also contested that "the data was not used for legitimate purposes, i.e., a commercial proposal, but rather to organize a potential fraud. In fact, the company contacted the number they had to report an administrative and technical anomaly in their area, without actually communicating that a contract was being signed. It should be noted that this circumstance clearly emerges from the audio recording filed by the professional himself during his initial counter-arguments; 2) as soon as he learned of the unlawful processing of his data, namely during the aforementioned voice recording, the professional should have acted immediately to verify the proper processing, whereas no action was taken until the date of the complaint to the Guarantor.

1.3. Rejection of the request for technical verification

The Office rejected the request for technical verification submitted by the Company to verify whether the IP address was actually traceable to the complainant's user account or internet connection, as it was manifestly irrelevant to the resolution of the proceedings and, in any case, inadmissible under the relevant regulatory principles.

In this regard, it was preliminarily noted that the IP address in question was associated with the acquisition of personal data on the offertegratis.com website and was not mentioned in the documentation relating to the campaign carried out on social networks.

Furthermore, the requested verification appeared irrelevant to the proceedings, given that, regardless of whether the IP address indicated could be traced back to the complainant, the forms used on the offertegratis.com website were not originally designed to obtain free, specific, and granular consent pursuant to current data protection legislation. Nor did there appear to be any correspondence between the aforementioned forms and the types of data held by the calling operator (i.e., banking and supply details).

As will be explained in detail below, regarding the offertegratis.com portal, an examination of the forms and information contained therein does not allow us to determine whether the provision of second and third consent, regardless of the choice of individual product categories, entails the transfer of personal data without distinction to all the numerous transferees listed therein. However, based on the forms used, such transfer is triggered by the flag for the third consent. In this regard, the Office, citing the Authority's most recent decisions, highlighted that the use of forms lacking transparency and/or that do not allow for the expression of free, specific, and granular consent is in direct violation of the applicable personal data protection regulations. The Office also noted that the Company, having limited itself to producing only a declaration provided by the list provider containing the timestamps, IP address, and personal data of the complainant, had not even provided sufficient evidence regarding the origin of the data. The website in question lacks any mechanism (such as double opt-in or similar) that would allow for the association of those expressions of consent with sufficient certainty with the data subjects and, therefore, the burden of proof for the data controller to be deemed fulfilled regarding the acquisition of valid consent from the data subject. Similarly, in the absence of such a control system, adequate measures to ensure that the processing of personal data is carried out in full compliance with the principle of accuracy of processing do not appear to be implemented.

Furthermore, only during the second response did Nuova Corrente claim to have acquired the complainant's data through a social media campaign. However, in this regard, the company limited itself to producing an invoice issued by Meta Platforms Inc. to Joseph Agency S.r.l.s. and an Excel file summarizing the ten acquired records, relating to "Promoting My Fibra Module" campaigns. Neither of these documents contains any reference to Nuova Corrente or the promotion of energy services. It follows that, regardless of the IP address, even in this regard, Nuova Corrente had not provided sufficient evidence to demonstrate from the outset the lawful acquisition of the complainant's data.

For completeness of argument, the Office also observed that the request in question was inadmissible since requesting the Authority to exercise its investigative and investigative powers to acquire evidence, for which the current legislation requires the burden of proof to fall on the requesting party, would constitute a clear and unacceptable circumvention of the principles set forth in Articles 5 and 24 of the Regulation, insofar as they require the data controller to demonstrate compliance with personal data protection legislation.

The principle just stated, in fact, constitutes a logical corollary of the existing rules regarding the burden of proof. In this sense, the consistent case law of the Supreme Court also militates, which recently reaffirmed the principle according to which «the case law of this Court is in fact stable in holding that, given the scope of action granted to the consultant's investigative power by art. 194 of the Code of Civil Procedure, paragraph 1, the expert witness is entitled to acquire all information necessary to answer the questions referred to him by the judge, "provided that these are ancillary facts falling within the strictly technical scope of the consultancy, and not facts and situations which, being directly underlying the parties' claims or objections, must necessarily be proven by them" (Civil Court, United Sections, Ruling, February 1, 2022, No. 3086).

Similarly, administrative jurisprudence has expressed itself in the same terms, stating that "Nor is it possible to make up for the identified deficiency through recourse to unofficial judicial investigative powers. It is true that in administrative proceedings, the ontological inequality of the parties with regard to evidence forms the basis of the so-called dispositive principle with an acquisitive method, according to which the Court can make up for evidentiary deficiencies resulting from the Administration's greater proximity to the evidence, but this This general rule certainly cannot overturn the fundamental principle that a person bringing a legal action must clearly indicate the subject matter of their claim. The Court believes that the possibility of the judge exercising ex officio investigative powers should be admitted, in theory, but that this prerogative must constitute a last resort. In any case, it remains firm that, even when the facts are not fully available to the appellant, the judge should never use his powers to investigate the true intention of the party beyond what is explicitly stated in the legal action, essentially replacing it and compromising the principle of absolute impartiality of the adjudicating body with respect to the interests at stake. The principle of dispositive action with the acquisitive method "cannot, however, ever be reduced to an absolute and general reversal of the burden of proof and, in any case, does not allow the administrative judge to substitute himself for the burdened party when the appellant is unable to prove the fact forming the basis of his action." (Regional Administrative Court of Campania, Section VI, July 15, 2014, No. 3962; State Council, Section V, November 10, 2010, No. 8006)" (Regional Administrative Court of Lazio-Rome, Section I bis, Ruling, June 24, 2015, No. 8639).

It was also noted that, by virtue of the provisions of Article 5 of the Regulation and the principle of accountability, the data controller is extremely free to choose the methods and means to meet the obligations arising from the applicable legislation on the protection of personal data. Consequently, this discretion also affects the means and methods chosen to fulfill the burden of proof, which in this case required the identification of consent-gaining techniques based on the principles of unequivocality, unchangeability, and certainty, thus capable of overcoming any disputes. of the interested party.

1.4.     Notification of violations

The Office, following the investigation, adopted the aforementioned notice of complaint no. 36361/26, in which, first of all, it observed that the promotional activities carried out by Nuova Corrente towards the complainant appeared to have been carried out without an adequate legal basis and, consequently, in violation of Articles 5, 6, and 7 of the Regulation and Article 130 of the Code.

Furthermore, the conduct just referred to also appeared to be particularly serious, since, according to the Company's statements, it had affected at least nine other interested parties.

From another and different perspective, the Office noted that Nuova Corrente appeared not to have yet fully assimilated the obligations arising from the principle of accountability, with particular regard to the lawfulness of the entire processing chain from contact to contract, nor the duties arising from the provisions of Article 28 of the Regulation.
Finally, it was noted that the case at hand also appeared to demonstrate a violation of Articles 12 and 15 to 22 of the Regulation regarding the exercise of data subjects' rights.

The Office therefore charged Nuova Corrente with the following violations:

- Articles 5, 6, and 7 of the Regulation, as well as Article 130 of the Code, for having carried out the above-described processing of personal data without an appropriate legal basis;

- Articles 5, 24, and 28 of the Regulation, for having carried out the above-described processing of personal data in violation of the duties arising from the principle of accountability and Article 28 of the Regulation;

- Articles 12 and 15 to 22 of the Regulation for failing to respond to the request to exercise rights submitted by the complainant and, more generally, for failing to adopt appropriate measures to ensure the adequate management of requests to exercise rights. by the interested parties.

2. THE OWNER'S DEFENSE

In a note dated April 8, 2026 (see Prot. No. 54361 of April 9, 2026), Nuova Corrente preliminarily emphasized that it was completely uninvolved in any alleged fraudulent and/or deceptive conduct against the complainant, as was also evident from the internal operator's demeanor during the verification call. In this regard, the Company argued that, given the concerns expressed by the user and the lack of a clear interest in concluding the contract, the operator had immediately acknowledged the interested party's disinterest, interrupted the contract activation process, and rejected the agency's contractual proposal. According to Nuova Corrente's defense, this conduct demonstrated that the direct contact phase—not even mandatory under industry regulations—was not merely aimed at automatically confirming the proposal, but rather constituted "a concrete control aimed at ensuring customer awareness and preventing unwanted activations.

On the same occasion, the Company highlighted that the existing agency agreement required Joseph Agency to "present Nuova Corrente's Services to Customers in a manner consistent with their actual characteristics, as indicated and described in the Offer, keeping up to date with the same," adhering to the call script provided, and that it was prohibited to "make inaccurate, misleading, and/or denigrating statements regarding the Services, and other products and/or services, including those of third parties." The use of the script was also referred to in the appointment as data controller, and the contract prohibited any changes to the scripts and the summary documentation prepared by the Principal. This script also stipulated that the supply data (POD and PDR) were requested by Joseph Agency, while the banking data were requested by Nuova Corrente for the purposes of concluding the contract. The agency agreement also provided for a "sanctioning mechanism, in the form of a penalty and non-payment of the commission, as well as reimbursement of costs and damages, for any results of the checks carried out by the principal and/or for any complaints received from Clients and/or potential Clients attributable to the activity referred to in the same contract, from which violations of criminal, civil, administrative laws and/or contractual obligations emerge.

Nuova Corrente further emphasized that the termination of the relationship with Joseph Agency S.r.l.s. was based on a lack of commercial production for purely prudential reasons, since "objective and documentary evidence capable of conclusively proving any conduct by the partner that did not comply with the contractual provisions was not yet available," although this decision was also prompted by the complainant's report, as a measure to immediately mitigate the alleged critical issues.

Regarding the alleged inadequacy of the supplier's controls, Nuova Corrente stated that the relationship with Joseph Agency S.r.l.s. had lasted approximately three and a half months and that no other irregularities had been recorded prior to that. Therefore, the lack of audits, even though they had been scheduled, was attributable to the short duration of the collaboration and the partner's reduced productivity.

Regarding the unsuitable legal basis for processing the complainant's data, the Company emphasized that the collection of personal data and consent from potential customers had been carried out by Joseph Agency S.r.l.s. using a third party, Clean Energy Consulting, whose name and role had never been disclosed to Nuova Corrente, in violation of the provisions of the appointment as data controller, thus hindering Nuova Corrente's oversight activity.

This lack of transparency had also led to contradictory statements provided during the proceedings regarding the origin of the data.

Regarding the failure to respond to the complainant's request to exercise her rights, Nuova Corrente argued that the request had been "managed and processed from an exclusively commercial perspective" and had not caused irreparable harm to the data subject. that this was an isolated incident resulting from the fact that the request had been sent to the Company's certified email address (PEC) and not to the email address dedicated to managing requests regarding personal data protection, as indicated in the privacy policy published on the Company's website. To prevent similar issues from recurring, Nuova Corrente had already integrated the management of requests for the exercise of privacy rights into its Ticketing/CRM system during the course of the proceedings. As a result, "each request received is now recorded with a 'Privacy Ticket' associated with a 30-day countdown. The system prevents the case from being closed until proof of the response sent to the interested party is uploaded, making it impossible for the request to be omitted due to forgetfulness or carelessness."

Nuova Corrente also stated that it had initiated a plan to strengthen its organizational structure and compliance controls through "the adoption of structured procedures for the qualification and selection of lead providers, based on criteria for the traceability and verifiability of sources; Introduction of advanced proof of consent systems (including double opt-in or equivalent mechanisms). The Company has planned to implement a telephone double opt-in protocol using Strong Authentication (SMS OTP). This system requires that consent (or the contract) be finalized by entering a unique code sent in real time to the data subject's mobile device. The procedure will ensure the digital traceability of the user's consent, uniquely associating the validation timestamp with the contacted user (...); comprehensive review of data processor appointments pursuant to Art. 28 GDPR; implementation of periodic audits and documented checks on partners; implementation of commercial scripts from the standpoint of transparency and fairness.

In addition, the Company expressed its willingness to adhere to the Code of Conduct for Telemarketing and Teleselling, "establishing as a privileged selection criterion for its partnerships that Agencies adhere to the same Code."

Finally, Nuova Corrente cited the mitigating circumstances applicable in this case and requested their application for the purposes of determining a possible financial penalty.

3. AUTHORITY'S ASSESSMENTS

First, it is noted that Nuova Corrente's observations, provided during the proceedings, do not appear to be sufficient to exclude the Company's liability for the alleged violations.

The promotional activities carried out by Nuova Corrente towards the complainant appear to have been carried out without an adequate legal basis and, consequently, in violation of Articles 5, 6, and 7 of the Regulation and Article 130 of the Code.

In fact, despite the burden of proof falling on the owner pursuant to Articles Pursuant to Articles 5 and 24 of the Regulation, the clarifications provided do not appear adequate to explain the source of the data subject's data, nor to demonstrate the existence of an appropriate legal basis for the processing, since the Company provided contradictory information on this point, not even supported by sufficient evidence.

Regarding the source of the data, the Company initially stated that the data was acquired through a form published on the website offertegratis.com, which was attributable to a Bulgarian company. Subsequently, Nuova Corrente stated that the complainant's personal data had also been acquired through social networks. The statements regarding the timeframe for obtaining consent also appear contradictory. Furthermore, both of the aforementioned data collection sources fail to explain why the calling operator, during the initial contact complained of, was also in possession of the data relating to supplies and banking information, as reported by the interested party pursuant to Article 13 of the Regulation. 168 of the Code and never disputed by the Company. This type of data is not among those requested on the offertegratis.com website, nor is it included in the Excel file detailing the ten personal data provided by Joseph Agency S.r.l.s.

More specifically, with respect to the offertegratis.com website, which is owned by the Bulgarian company Clean Energy Consulting, it should be noted that the formulas at the bottom of the form therein are not suitable for obtaining valid consent pursuant to Articles 4, point 11, and 7 of the Regulation, as they present multiple critical elements.

At first glance, in fact, the formulas used for the transfer of data to third parties for promotional purposes appear to be overlapping (i.e., second and third consent), with the sole difference that only the second form contains the link apparently useful for making a differentiated choice based on product categories. Secondly, the complete list of third parties displayed next to the flags differentiated by the transferee's product category is always the same (see second consent). This same list can also be accessed via the link within the third consent form. In other words, this form structure makes it difficult to determine whether granting the second and third consents, regardless of the choice of individual categories, entails the transfer of personal data without distinction to all the numerous transferees listed therein. Furthermore, even granting the third consent alone entails the transfer of personal data without distinction to all operators belonging to the numerous and diverse product categories indicated therein, without the data subject's ability to make a free, specific, and granular choice, resulting in a loss of control over their personal information.

The principle according to which the use of formulas lacking in transparency and/or which do not allow for the expression of free, specific and granular consent is in open conflict with the current legislation on the protection of personal data; this has, moreover, been repeatedly reiterated by the Authority also in its most recent resolutions (see Provision no. 114 of 27 February 2025, available for consultation on the website www.gpdp.it, web doc. no. 10114967, where it is stated that «Due to the broad wording used in relation to the large and indistinct group of transferees of personal data operating in very different sectors, in fact, the interested party who wishes to receive offers relating to one or more of the product categories indicated therein or wishes to receive them through only one of the channels indicated is, in fact, forced to give a single consent to the indiscriminate transfer of his/her data to all, without distinction, third party recipients for promotional purposes and is not placed in a position to easily exercise the rights recognised by the current legislation (…) The use of such broad and specific formulas for the acquisition of consent to the processing of personal data for the transfer to third parties for marketing purposes generic, which does not allow the interested party to express a granular and differentiated will, for example in relation to the product category of the commercial offers he wishes to receive (i.e. telephony, energy supplies, insurance services, fashion, cars, etc.) or which, due to the particular configurations of the forms and information used, does not allow him to easily express his will regarding the tools through which promotional communications are conveyed, does not allow for the acquisition of a valid, conscious and unequivocal expression of will from the interested party, since it ends up creating an uncontrollable dissemination of personal data in favour of an indistinct audience of operators, also undermining the possibility of effectively exercising the rights recognised by law in favour of the interested parties» ).

In other words, the expression of will regarding the transfer of data to third parties for marketing purposes can be considered truly free only if the data subject is guaranteed an effective choice and control over his or her personal data (see Guidelines no. 5/2020 on consent pursuant to Regulation (EU) 2016/679, available for consultation on the website www.edpb.europa.eu, paragraph 3.1 "The element of 'free' expression of will implies that the data subject has an effective choice and control over his or her data. As a general rule, the Regulation establishes that if the data subject does not have an effective choice or feels obliged to consent or will suffer negative consequences if he or she does not consent, the consent will not be valid. If consent is a non-negotiable element of the general terms and conditions of a contract/service, it is presumed that it was not given freely. Consequently, consent will not be considered free if the data subject cannot refuse or withdraw it without suffering detriment. The General Data Protection Regulation "The Data Protection Authority (DPA) also took into account the notion of imbalance between the controller and the data subject" and paragraph 3.1.3 "If the controller has combined different processing purposes and has not requested separate consent for each of them, there is no freedom. Granularity is closely related to the need for specific consent, as analyzed in section 3.2. When data processing is aimed at pursuing different purposes, the solution to satisfying the conditions for valid consent lies in granularity, i.e., the separation of purposes and obtaining consent for each of them.").

On this point, it is also noted that Nuova Corrente's claims regarding the origin of the complainant's data do not even appear to be supported by sufficient evidence and, in any case, have been repeatedly contested by the applicant, who, in making declarations pursuant to Article 168 of the Code, denied having consulted the referenced websites and provided his personal data.

Regarding the offertegratis.com website, the Company had only provided a declaration issued by the list provider containing the timestamps, IP address, and personal data of the complainant, which, however, lacked the requirements of certainty, unequivocality, and unalterability.

Similarly, even with respect to the personal data acquired via social networks, the evidence provided by the Company appears to lack the aforementioned requirements and, as a result, does not allow the objections raised by the interested party to be refuted. Nuova Corrente merely produced an Excel file and an invoice issued by Meta Platforms, Inc. to Joseph Agency S.r.l.s., relating to "Promoting the My Fibra Module" campaigns, but this documentation lacks any reference to Nuova Corrente or the promotion of energy services.

The consent acquisition systems used on the offertegratis.com portal and on social networks, in fact, do not appear to be adequately equipped with measures to verify the identity of the person entering personal data in the form and, therefore, to unequivocally prove that consent has been given.

The Authority has also repeatedly highlighted the inadequacy of consent acquisition systems lacking any measures to verify the identity of the person entering personal data in the form (such as (e.g., double opt-in), noting that such mechanisms do not allow for the association of those expressions of will with sufficient certainty with the data subjects and, therefore, the burden of proof on the data controller regarding the acquisition of valid consent from the data subject to be deemed fulfilled. Similarly, in the absence of a control system, adequate measures to ensure that the processing of personal data is carried out in full compliance with the principle of accuracy of processing do not appear to be implemented.

It should be added that these findings are even more stringent when considered in the current socio-economic and technological context, characterized by the spread of non-navigable websites featuring only contact collection forms, used for the sole purpose of giving a semblance of lawfulness to contact lists acquired outside of the legal requirements.

The Authority recently examined this issue in depth with Provision No. 330 of June 4, 2025, web doc No. 10143278, ruling that Furthermore, with regard to the lack of an express regulatory requirement to qualify consent as a double opt-in, it is noted that—contrary to what the NCA maintains—one of the requirements for lawful consent under Article 7 of the Regulation includes the obligation for the data controller to demonstrate that the data subject has given his or her consent. This demonstration, although it is now known in the current state of the art, cannot be considered sufficiently demonstrated by the presentation of stamps—qualified as log files—containing data often unknown to the data subjects, lacking the IT requirements of unalterability, and concerning lists consisting of subjects, often located outside the EU, who do not offer adequate guarantees. In this context, it must first be taken into account that the Regulation does not expressly provide specific regulatory obligations for individual cases but requires compliance with general principles that must be adapted to the context, potential risks, and expectations of the data subjects. Starting from this assumption, the Garante has repeatedly provided guidance on specific cases, recalling that the documentation of consent in a double opt-in manner is essential. Double opt-in is a form of consent documentation that offers greater guarantees and can be considered, given the current state of the art, a minimum protection measure for the data subject but also for the data controller, who is required to demonstrate the lawfulness of the processing (see, for example, www.garanteprivacy.it, provision of December 15, 2022, web doc 9852290, provision of October 26, 2017, web doc no. 7320903, and provision of November 25, 2021, web doc no. 9737185); similar methods of consent documentation are also indicated in the Code of Conduct for Telemarketing and Teleselling (provision of March 7, 2024, web doc no. 9993808).

Provision no. 574 of May 9, 2024, available for consultation on the website www.gpdp.it, web doc. n. 10107938, the Authority observed that the choice to "implement the described procedure of sending an SMS to allow the data subject to revoke their availability for recontact does not appear to be functional to discourage the possible use of bots that, massively, can enter telephone numbers to be recontacted, given that the two-minute limit within which the data subject can exercise such reconsideration is clearly not suitable to protect those who have been unknowingly entered into the recontact mechanism and who find themselves receiving a mysterious SMS in which, moreover, it is suggested to activate a link (a practice widely discouraged to avoid introducing malware into one's devices). More effective, in this sense, seems to be a "confirmation" procedure of consent to recontact (by clicking a specific link or entering an OTP sent via SMS in the web form) without which the recontact itself would not take place."

Considering the numerous and detailed indications provided by the Authority on the matter, Nuova Corrente, in its capacity as data controller and in fulfilling its duties, including those deriving from the principle of accountability, could and should have realized that this source of personal data, which was also used for the purposes of carrying out promotional activities in its interest and from which it derived financial benefit, was in open violation of the provisions in force regarding the protection of personal data and of the Authority's most recent arrests.

In this regard, the Company's representation regarding the lack of awareness of Clean Energy Consulting's role cannot be considered mitigating or exculpatory, given that both the contract signed with Joseph Agency and the attached appointment as data processor contained reference to the possibility of using other individuals and collaborators in fulfilling the mandate conferred. It should be added that the conduct described above also appears to be particularly serious, given that, by the Company's own admission, it involved at least nine other interested parties.

More In general, Nuova Corrente appears not to have fully assimilated the obligations arising from the principle of accountability, particularly with regard to the lawfulness of the entire processing chain from contact to contract, nor the obligations arising from the provisions of Article 28 of the Regulation.

In the first regard, the Company appears to have completely delegated the choice of data procurement methods to the agency, without having bothered to identify upstream selection criteria or carry out effective downstream checks. In this regard, mere references to the lawful origin of the lists or contractual obligations cannot be considered sufficient. Nor is there any evidence in the proceedings regarding the implementation of the aforementioned random and periodic checks.

Article 5 of the Code of Conduct on telemarketing and teleselling applies in this regard (see Decision No. 70 of March 9, 2023, web doc. No. 9868813 and Decision No. No. 148 of 7 March 2024, web doc. No. 9993808), which, regardless of actual compliance, assumes the value of best practices in the sector, in the part where it clarifies that "Without prejudice to the division of responsibilities and the provisions of the previous Article 4 regarding joint liability, the data controller guarantees and requires its processors that the processing, starting from the data collection phase, is carried out in compliance with the Regulation, the Code and this Code of Conduct. To this end, the data controller adopts adequate measures to verify that the data processor complies with the instructions given through audit mechanisms such as, for example, "teaser numbers" (own numbers within the list of contactable numbers) and random checks on contracts entered into, to verify that contacts are carried out in the manner established by the data controller and in compliance with Articles 6 and 11 of this Code of Conduct and that, in particular, the information has been provided in an intelligible manner."

In this regard, the Company observed that the lack of controls over Joseph Agency was caused by the short duration of the contractual relationship. However, this objection cannot be upheld given that Nuova Corrente has not provided any evidence—not even documentary evidence—to prove that such activities were planned and systematically carried out within its corporate structure, for example, through the formalization of an ad hoc procedure or the implementation of controls on other business partners.

Similarly, also with regard to the relationships with Joseph Agency S.r.l.s., the evidence emerging during the proceedings has made it possible to ascertain the occurrence of conduct contrary to the provisions of Article 28 of the Regulation (so-called culpa in eligendo and culpa in vigilando).

First, the forms used to appoint the responsible party—which were not even duly completed—refer to provisions that have now been repealed.

Although Article 28 of the Regulation While Article 28 of the Regulation requires the use of partners with adequate privacy expertise, the criteria cited for pre-qualification of suppliers (i.e., being an Italian company duly registered in the Register of Communications and Postal Operators) have little to do with personal data protection, as they relate instead to financial solvency and the required communications qualifications.

Furthermore, the proceedings do not even provide evidence of the issuance of relevant instructions regarding the execution of promotional contacts, nor of the implementation of adequate controls over the data controller's work.

The fraudulent and deceptive conduct of the telephone operator during the first of the contacts at issue, as described by the complainant and corroborated by the recording of the second call, supports this view. Similarly, the termination of the contract signed with the agency makes no reference to the violation of personal data protection legislation and, in any case, was carried out before the complaint was even filed with the Authority. Finally, it is noted that the events in this case also reveal a violation of Articles 12 and 15 to 22 of the Regulation regarding the exercise of rights by data subjects.

In fact, despite the burden of proof falling on the data controller, the Company has in no way demonstrated that, prior to the initiation of today's proceedings, adequate measures had been implemented to ensure the adequate management of requests for the exercise of rights. Nor, with regard to today's complainant, has Nuova Corrente offered any valid excuse for its failure to respond to her duly submitted request.

In this regard, the Company argued that the request had been "managed and processed from an exclusively commercial perspective," but this argument is not persuasive since the subject and body of the request made express and unequivocal reference to the legislation on personal data protection, while no commercial prerogative or right of withdrawal was mentioned. The objection that the request was sent to the Company's certified email address and not to the email address dedicated to managing requests regarding personal data protection is also irrelevant, since the current legislation does not impose any specific formalities on this point. Therefore, the data controller is required to respond to requests regarding rights, regardless of the channel and form used, unless one of the circumstances set out in Article 12, paragraph 5, of the Regulation applies or the grounds for the exclusions provided for in relation to the individual rights granted to data subjects exist.

In this context, while appreciating the corrective measures already spontaneously implemented during the proceedings and those imminently adopted, Nuova Corrente's liability for the alleged violations must be definitively confirmed.

4. CONCLUSIONS

Based on the above, Nuova Corrente's liability for the following violations is deemed established:

- Articles 5, 6, and 7 of the Regulation, as well as Article 130 of the Code, for having carried out the aforementioned processing of personal data without an appropriate legal basis;

- Articles 5, 24, and 28 of the Regulation, for having carried out the aforementioned processing of personal data in violation of the duties deriving from the principle of accountability and Article 28 of the Regulation;

- Article 12 and 15 to 22 of the Regulation for the failure to respond to the request to exercise rights submitted by the complainant and, more generally, for the failure to adopt appropriate measures to ensure the adequate management of requests to exercise rights by data subjects.

Having also established the unlawfulness of the Company's conduct with regard to the processing under consideration, it is necessary to issue an injunction order, pursuant to Articles 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, for the application against Nuova Corrente of the administrative pecuniary sanction provided for by Article 83, paragraphs 3 and 5, of the Regulation.

5. INJUNCTION ORDER FOR THE APPLICATION OF THE ADMINISTRATIVE PECUNIARY SANCTION

The above-mentioned violations require the issuance of an injunction order, pursuant to Articles 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, for the application to Nuova Corrente of the administrative pecuniary sanction provided for by Article 83, paragraphs 3 and 5, of the Regulation.

More specifically, pursuant to Article 83, paragraph 3 of the Regulation, "If, for the same or linked processing operations, a controller or processor intentionally or negligently infringes several provisions of this Regulation, the total amount of the administrative pecuniary sanction shall not exceed the amount specified for the gravest infringement." Pursuant to the following paragraph. 5 "(…) infringement of the following provisions shall be subject to administrative fines up to EUR 20 million, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including the conditions for consent, pursuant to Articles 5, 6, 7, and 9; (b) the rights of data subjects pursuant to Articles 12 to 22; (c) transfers of personal data to a recipient in a third country or an international organization pursuant to Articles 44 to 49; (d) any obligation under the laws of the Member States adopted pursuant to Chapter IX; (e) non-compliance with an order, a temporary or definitive restriction on processing, or an order to suspend data flows from the supervisory authority pursuant to Article 58(2), or refusal of access in violation of Article 58(1)."

Since the specific case has been found to have violated Articles 5, 6, 7, 12, 15 to 22, 24, and 28 of the Regulation, as well as Article 130 of the Code, the provisions of Article 83, paragraphs 3 and 5 of the Regulation apply. Furthermore, reference must also be made to Nuova Corrente's turnover, as derived from the acquired economic and tax information. Therefore, in the case in question, pursuant to Article 83, paragraphs 3 and 5 of the Regulation, the maximum statutory fine is set at €20,000,000.

To determine the amount of the fine, the elements indicated in Article 83, paragraph 2 of the Regulation must be taken into account.

In this case, the following are relevant:

1) the seriousness of the violations (Article 83, paragraph 2, letter a) of the Regulation), taking into account the object and purpose of the data processed, which are attributable to the overall phenomenon of telemarketing. The Authority has adopted numerous measures, particularly over the last five years, that have fully examined the many critical elements, providing data controllers with extensive guidance on how to adapt processing to current legislation and mitigate the impact of nuisance calls on data subjects;

2) as a mitigating factor (Article 83, paragraph 2, letter f) of the Regulation), the degree of cooperation with the Supervisory Authority in addressing the violations;

3) as a further mitigating factor (Article 83, paragraph 2, letter g) of the Regulation), the categories of personal data affected by the violation (i.e., common data).

Based on the above-mentioned elements, and on the principles of effectiveness, proportionality, and dissuasiveness set forth in Article 83, paragraph 1, of the Regulation, and taking into account the necessary balance between data subjects' rights and freedom of enterprise, also to limit the financial impact of the fine on the Company's organizational and functional needs, it is deemed appropriate to impose on Nuova Corrente the administrative penalty of €15,000.00, equal to 0.075% of the maximum statutory fine.

In this case, it is deemed appropriate to apply the additional penalty of publishing this provision on the Garante's website, as provided for by Article 166, paragraph 7 of the Code and Article 16 of the Garante's Regulation No. 1/2019, taking into account the nature of the Company's processing and conduct, as well as the risks to the rights and freedoms of data subjects.
In implementation of the principles set forth in Article 83, paragraph 1, of the Regulation, it is deemed appropriate to impose the additional penalty of publishing this provision on the Garante's website. 83 of the Regulation, the imposition of this additional sanction appears reasonable and proportionate in relation to the particular negative value of the conduct being criticized, especially considering its gravity, as it pertains to the fundamental - and constantly reiterated - principles of the legislation on the protection of personal data.

Finally, the conditions set out in Article 17 of Regulation No. 1/2019 concerning internal procedures of external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Guarantor, are met.

NOW CONSIDERING ALL THE ABOVE, THE GUARANTOR

pursuant to Article 57, paragraph 1, letter a), of the Regulation, declares the processing carried out by Nuova Corrente S.r.l., with registered office in Vibo Valentia (VV), Via Spogliatore, S.N.C., VAT No. 12126890966, to be unlawful, in accordance with the reasons given in the decision;

ORDER

Nuova Corrente S.r.l., represented by its legal representative pro tempore, with registered office in Vibo Valentia (VV), Via Spogliatore, S.N.C., VAT No. 12126890966, to pay the sum of €15,000.00 (fifteen thousand/00) as an administrative fine for the violations indicated in the grounds. It is hereby stated that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by complying with the provisions established and paying, within thirty days, an amount equal to half of the fine imposed.

ORDERS

the aforementioned Company, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €15,000.00 (fifteen thousand/00), according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981.

ORDERS

a) the publication of this order, pursuant to Articles 154-bis of the Code and 37 of Regulation No. 1/2019;

b) the application of the accessory sanction of publication of this injunction on the website of the Guarantor, as provided for by Articles 166, paragraph 7 of the Code and 16 of the Guarantor Regulation No. 1/2019;

c) the annotation of this order in the Authority's internal register - provided for by Article 57, paragraph 1, letter u) of the Regulation, as well as Article 17 of Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers assigned to the Guarantor - relating to violations and the measures adopted in accordance with Article 58, paragraph 2, of the Regulation itself.

Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150 of 1 September 2011, an appeal against this decision may be lodged with the ordinary judicial authority, with an appeal filed with the ordinary court of the place where the data controller resides, or, alternatively, with the court of the place of residence of the data subject, within thirty days of the date of notification of the decision itself, or sixty days if the appellant resides abroad.

Rome, April 29, 2026

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Montuori


[web doc. no. 10255198]

Measure of April 29, 2026

Register of Measures
no. 312 of April 29, 2026

THE DATA PROTECTION AUTHORITY

IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;

HAVING REGARD to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the "Regulation");

HAVING REGARD to the Personal Data Protection Code (Legislative Decree No. 196 of 30 June 2003), as amended by Legislative Decree No. 101 of 10 August 2018, containing provisions for the adaptation of national law to the aforementioned Regulation (hereinafter the "Code");

HAVING REGARD to the documentation in the file;

HAVING REGARD to the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Garante No. 1/2000, adopted by resolution of 28 June 2000;

RAPPORTEUR: Prof. Pasquale Stanzione;

1. INVESTIGATIVE ACTIVITY CARRIED OUT

1.1. Introduction

With document no. 36361 of March 10, 2026, notified on the same date by certified email, which is reproduced here in its entirety, the Office initiated, pursuant to Article 166, paragraph 5, of the Code, a proceeding for the adoption of the measures referred to in Article 58, paragraph 2, of the Regulation against Nuova Corrente S.r.l. (hereinafter "Nuova Corrente" or the "Company"), represented by its legal representative pro tempore, with registered office in Vibo Valentia (VV), Via Spogliatore, s.n.c., VAT no. 12126890966.

The proceeding stems from an investigation initiated by the Authority following the receipt of a complaint. The interested party complained of receiving two fraudulent promotional calls, made on behalf of Nuova Corrente, and of the inadequate response to the request submitted pursuant to Article 15 of the Regulation. Specifically, the interested party claimed that the initial contact had been made by an external company claiming to be the local distributor and alleged a double billing error, warning that the interested party would be contacted again by a company called "Nuova Corrente." The second contact was made by a Nuova Corrente operator and was aimed at concluding a new supply contract. Therefore, the interested party contacted the Authority to obtain the protections recognized by current legislation on the protection of personal data.

1.2. Requests for information made by the Authority

Having examined the complaint and all the attached documentation, with a note dated October 13, 2025 (see Prot. No. 135446/25), the Office invited Nuova Corrente, pursuant to Article 157 of the Code, to submit its observations regarding the content of the complaint.

Subsequently, with a note dated November 3, 2025 (see Prot. No. 145522/25), the Company first responded to the interested party's original request for access, clarifying in particular that the complainant's personal data had "been acquired under an agency agreement entered into with the company JOSEPH AGENCY S.R.L.S. (…), duly registered in the Register of Communications Operators (…). This company had been entrusted (…) with carrying out promotional and customer acquisition activities, with specific contractual obligations regarding the protection of personal data. In turn, Joseph Agency S.r.l.s. acquired Ms. Ferrario's contact information from the company Clean Energy Consulting, which collected the data via the web portal https://offertegratis.com/informativaPrivacy."

On the same occasion, Nuova Corrente also stated that only personal and contact information had been processed for promotional purposes and on the basis of the consent granted by the interested party "as shown in the electronic registration record (...), dated July 18, 2025, at 2:18:04 PM, from address XX (...) following consultation of the privacy policy on the website https://offertegratis.com/informativaPrivacy."

Nuova Corrente acknowledged the process described by the complainant—who had received an initial call from Joseph Agency S.r.l.s. and a second from an internal Nuova Corrente operator to finalize the contract—and produced the recording of the second call, noting that "Listening to the recording unequivocally reveals the courtesy and professionalism demonstrated by the Nuova Corrente operator. Having noted the user's discomfort and acknowledged his disappointment at not having received any information and his refusal to receive it, she concluded the conversation by thanking Ms. Liliana with a 'thank you very much.'"

Finally, the Company documented that "In a spirit of full accountability (Article 5, paragraph 2, and Article 24 GDPR), and following an internal assessment, Nuova Corrente S.r.l. deemed the performance and operating methods of the aforementioned agency to be unsatisfactory. Therefore, on July 31, 2025, the undersigned formally notified Joseph Agency S.r.l.s. The immediate termination of the agency mandate, as a corrective measure aimed at preventing the recurrence of similar situations and ensuring a higher standard of protection for data subjects.

In a note dated November 10, 2025 (see Prot. No. 149791 of November 12, 2025), the interested party submitted its observations, highlighting that the Company had responded to the request for access only following the request notified by the Authority and that "the aforementioned online service where the data would have been entered was never used, neither on the date indicated nor on any other date, and the dynamics appear highly unlikely, given that it is a Bulgarian-Canadian website."

In the note in question, the interested party also highlighted that "the data was not used for legitimate purposes, i.e., a commercial proposal, but rather to organize a potential fraud. In fact, the company contacted the number they had to report an administrative and technical anomaly in their area, without actually communicating that a contract was being signed. It should be noted that this circumstance is clearly evident from the audio recording filed by the professional himself during his counter-arguments and that "as soon as he learned of the unlawful processing of his data, namely during the aforementioned voice recording, the professional should have acted immediately to verify the proper processing, whereas no action was taken until the date of the complaint to the Guarantor."

Subsequently, following an access by the Office to the site offertegratis.com, attributable to the Bulgarian company Clean Energy Consulting, it emerged that:

- the portal is not navigable in any way, but only contains a form for collecting personal data (i.e.,name, surname, telephone number, email address) and consent from users («I have read and accept the information»; «I consent to the processing of my personal data for the sending, by offertegratis.com, of promotional communications relating to products and/or services of offertegratis.com or companies associated with it, with the use of telephone with operator and/or also through automated systems (e.g. email, SMS)»; «I consent to the transfer for marketing and commercial purposes, with the use of telephone with operator and/or automated systems (e.g. email, SMS) and/or sending of promotional material by post, to third parties belonging to different economic or product categories. Click here to manage them»; «I consent to the transfer for marketing and commercial purposes, with the use of telephone with operator and/or automated systems (e.g. email, SMS) and/or sending of promotional material by post, to third parties belonging to different economic or product categories. Click here to manage them»; «I consent to the transfer for marketing and commercial purposes, with the use of telephone with operator and/or automated systems (e.g. email, SMS) and/or sending of promotional material by post, to third parties belonging to different economic or product categories. Click here to manage them»; part of the following economic or product categories: Tourism, Leisure, High-Tech, Fashion, Furniture, Consumer Goods, Food & Beverage, Finance, Banking, Insurance, Energy, Environment, Communications, Media, Entertainment, Real Estate, Pharmaceuticals, Automotive, Clothing and Textiles, Training, Energy, Publishing, ICT, Retail, Sports, Telecommunications, and Services in general (Transfer Information); however, the formulas used to obtain the second and third consents appeared to overlap;

- clicking on the "Click here to manage them" link opened a second banner allowing users to grant different consents by product sector, and at the bottom of each sector was the link "Here you can view the complete list," which allowed users to always consult the same "Transfer Information" where numerous owners and an equally numerous product categories were listed;

- clicking on the "Transfer Information" link redirected the user to the same information as in the previous point.

Therefore, in light of the findings and documentation provided, as well as the findings made by the Office, it was appropriate to conduct a further investigation, sending the Company a request for additional information pursuant to Articles 58, paragraph 1, letter a) of the Regulation and 157 of the Code (see Protocol No. 178264 of December 23, 2025).

With a note dated January 12, 2026 (see Protocol No. 3405 of January 13, 2026), Nuova Corrente preliminarily stated that it had acquired from JOSEPH AGENCY S.R.L.S. a total of ten personal data records, which "according to the partner's declaration, originate from lists available to it, acquired from qualified third-party providers who have certified the lawfulness of the collection and the existence of a suitable legal basis for the promotional contact."

Nuova Corrente also clarified that the telemarketing and teleselling activities carried out on its behalf were "conducted via direct telephone contact. The operational flow includes: presentation of the offer, explanation of the financial terms, obtaining consent, transmission of the contractual proposal, and subsequent contract validation by Nuova Corrente S.r.l."

Regarding the parties involved in carrying out the aforementioned activities, the Company stated that "Nuova Corrente S.r.l. acts as Data Controller for the contract validation and customer management phases. JOSEPH AGENCY S.R.L.S. has been formally appointed as Data Processor (pursuant to Article 28 of the GDPR) for telephone contact and promotional activities. The actual contact operators act as authorized persons under the direct responsibility of the Data Processor."

Regarding the selection of list providers, Nuova Corrente clarified that this activity "is delegated to the Data Processor, who has the contractual obligation to select compliant suppliers and obtain certifications of lawfulness."

Nuova Corrente further stated that it had provided binding written instructions through the deed of appointment as Data Processor and contractually provided for random checks on call quality and periodic document checks to ensure process compliance. Furthermore, "The Data Processor declared that it would carry out preliminary consistency and traceability checks, including verifying consent and cross-checking with the Public Register of Oppositions (RPO). Nuova Corrente S.r.l. conducts random and second-level checks in the event of reports or anomalies."

Regarding the remedial measures adopted in the event of illicit contacts, the Company stated that it would adopt "immediate corrective measures: suspension of the registry, request for urgent clarification from the partner, and, in the most serious cases, termination of the relationship," reiterating that the mandate granted to JOSEPH AGENCY S.r.l.s. had expired on July 31, 2025, due to performance and operating procedures deemed unsatisfactory.

Finally, Nuova Corrente stated that it had "an internal procedure that provides for the receipt, recording, and involvement of the Data Controller to provide feedback to the data subject within the legal deadlines" and requested a brief extension of the originally granted deadline to acquire the documentation held by JOSEPH AGENCY S.r.l.s. This extension was granted with note Prot. No. 5294 of January 15, 2026.

Thus, in a further response sent on January 27, 2026 (see Prot. No. 11635 of January 28, 2026), the Company preliminarily noted that "During the period under investigation, the data flow managed through the commercial partner Joseph Agency S.r.l.s. was extremely limited, limited to a total of 10 records. These contacts did not result from bulk purchases of "cold" lists, but rather from targeted digital lead generation activities. As evidenced by the attached tax documentation (Meta Platforms Ireland Ltd. invoices), the acquisition occurred through advertising campaigns on social media platforms (Facebook/Instagram), managed by the partner in compliance with applicable advertising policies.

The Company also stated that "Nuova Corrente S.r.l.'s promotional activity is strictly subject to prior consent verification. Telephone contact with users occurs exclusively following the receipt of a qualified lead, accompanied by technical logs (IP and timestamp). During the call, the operator verifies the caller's identity and renews the information, proceeding with the commercial proposal only if there is a clear expression of interest."

Regarding the assignment of the mandate to Joseph Agency S.r.l.s., Nuova Corrente specified that the choice "was not random, but based on criteria of formal and substantial reliability. The partner is an Italian corporation duly registered in the Register of Communications Operators (...). This registration constitutes, for the Data Controller, a qualified indicator of professionalism and compliance with industry regulations.

Regarding the documentary evidence regarding the source of the complainant's data, Nuova Corrente stated that "The technical evidence in our possession, consisting of registration metadata and proof of advertising investments made by the partner on the Meta platform (...), unequivocally confirms that the data was generated in a lawful and tracked acquisition context, as documented in the attachment entitled "free lead generation contacts." Further confirming the authenticity of the collection, a thorough analysis of the web traffic logs revealed a crucial element: the complainant's consent was given on two separate occasions. In addition to the first tracking, a second expression of consent was found directly through the Facebook platform. This circumstance, certified by the system logs, rules out the possibility of involuntary or automated input, confirming the user's genuine interest in the commercial proposal."

Furthermore, in light of the complainant's allegations, the Company requested "to arrange, as part of this investigation, a technical assessment to verify whether the address XX can actually be traced back to the complainant's user account or internet connection."

In a note dated January 30, 2026 (see Prot. No. 14184 of February 2, 2026), the complainant noted that "no reason is provided either for the failure to respond to the initial request for access to her data, or for the fact that the data was used for purposes bordering on fraud, given that the personal data was used to report a technical fault/anomaly in the area and not, as in reality, for a commercial offer. Both of these matters, also frankly admitted by the opposing party, are reflected in the audio recording already filed by them."

Furthermore, regarding the origin of the personal data, the interested party highlighted that "1) the counterparty's documentation does not in any way reveal a univocal correspondence between the use of this IP and the declaration of consent to the use of the data; 2) the fact that a data acquisition invoice was paid to Meta does not guarantee that the data was acquired lawfully nor that the invoice concerns one's personal data and/or that of other potential customers; 3) (...) it is at least controversial that in the previous counter-argument Nuova Corrente srl had declared that the data had been acquired by the Bulgarian company Clean Energy Consulting via the offertegratis.com platform (a website registered in Canada), while in this case the data would have been acquired via Facebook by Meta, based in Dublin, a sign that evidently there is no certainty as to the origin of the data; 4) It can however be ruled out that the data was acquired through these platforms. In fact, the call center operator, upon the first call received, had not only the personal and contact details, but also the POD and PDR codes for the supply and even the bank IBAN, information that is normally acquired exclusively through data breaches of other electricity and gas suppliers. This is because online comparison platforms do not require either POD, PDR, or bank IBAN, which are acquired directly from the supplier only during the contract signing phase. Furthermore, "in the first counter-argument (…), the electronic trace would report the date of 07/18/2025 (…). In the second counter-arguments, Nuova Corrente srl instead declares that consent from the contested IP address would have occurred on 07/04/2025."

The complainant also claimed that "the data was used not for legitimate purposes, i.e., a commercial offer, but rather to organize a potential fraud. In fact, the company contacted the number they had to report an administrative and technical anomaly in their area, without actually communicating that a contract was being signed. It should be noted that this circumstance is clearly evident from the audio recording filed by the professional himself during his initial counterarguments; 2) as soon as the professional learned of the unlawful processing of his data, i.e., during the aforementioned voice recording, he should have acted immediately to verify the proper processing, whereas no action was taken until the date of the complaint to the Data Protection Authority."

1.3. Rejection of Request for Technical Verification

The Office rejected the request for technical verification submitted by the Company to verify whether the IP address was actually traceable to the complainant's user account or internet connection, as it was manifestly irrelevant to the outcome of the proceedings and, in any case, inadmissible under the relevant regulatory principles.

In this regard, it was preliminarily noted that the IP address in question was associated with the acquisition of personal data on the offertegratis.com website and was not mentioned in the documentation relating to the campaign carried out on social networks.

Furthermore, the requested investigation appeared to be irrelevant to the proceedings, given that, regardless of whether the IP address indicated was traceable to the complainant, the forms used on the offertegratis.com website were not originally designed to obtain free, specific, and granular consent pursuant to current data protection legislation. Nor did there appear to be any correspondence between the aforementioned forms and the types of data held by the calling operator (i.e., banking and supply details).

As will be fully explained below, regarding the offertegratis.com portal, an examination of the forms and information contained therein does not allow us to determine whether the provision of second and third consent, regardless of the choice of individual product categories, entails the transfer of personal data without distinction to all the numerous transferees listed therein. However, based on the forms used, such transfer is triggered by the flag for the third consent. In this regard, the Office, citing the Authority's most recent decisions, highlighted that the use of formulas lacking transparency and/or that do not allow for the expression of free, specific, and granular consent is in direct violation of current personal data protection legislation. The Office also noted that the Company, having limited itself to providing only a declaration provided by the list provider containing the timestamp, IP address, and personal data of the complainant, had not even provided sufficient evidence regarding the source of the data. The website in question, in fact, lacks any mechanism (such as double opt-in or similar) that would allow for the association of those expressions of consent with sufficient certainty with the data subjects and, therefore, the burden of proof for the data controller regarding the acquisition of valid consent from the data subject has been fulfilled. Similarly, in the absence of such a control system, adequate measures to ensure that the processing of personal data is carried out in full compliance with the principle of accuracy of processing do not appear to be implemented.

Furthermore, only during the second investigation did Nuova Corrente claim to have acquired the complainant's data through a social media campaign. However, in this regard, the Company limited itself to producing an invoice issued by Meta Platforms Inc. to Joseph Agency S.r.l.s. and an Excel file summarizing the ten acquired records, relating to "Promoting My Fibra Module" campaigns. Neither of these documents contained any reference to Nuova Corrente or the promotion of energy services. Consequently, regardless of the IP address, even in this regard, Nuova Corrente had not provided sufficient evidence to demonstrate the lawful acquisition of the complainant's data from the outset.

For the sake of completeness, the Office also observed that the request in question was inadmissible since requesting the Authority to exercise its investigative and investigative powers to acquire evidence, for which the current legislation requires the burden of proof to fall on the requesting party, would constitute a clear and unacceptable circumvention of the principles set forth in Articles 5 and 24 of the Regulation, insofar as they require the data controller to demonstrate compliance with personal data protection legislation.

The principle just stated, in fact, constitutes a logical corollary of the existing rules regarding the burden of proof. This is also supported by consistent Supreme Court case law, which recently reaffirmed the principle that "the case law of this Court is in fact stable in holding that, given the scope of action granted to the consultant's investigative power by Article 5, the data subject is entitled to a duty to provide evidence in the event of a breach of the law." 194 of the Code of Civil Procedure, paragraph 1, the expert witness is entitled to acquire all information necessary to answer the questions referred to him by the judge, "provided that these are ancillary facts falling within the strictly technical scope of the consultancy, and not facts and situations which, being directly underlying the parties' claims or objections, must necessarily be proven by them" (Civil Court, United Sections, Ruling, February 1, 2022, No. 3086).

Similarly, administrative jurisprudence has expressed itself in the same terms, stating that "Nor is it possible to make up for the identified deficiency through recourse to unofficial judicial investigative powers. It is true that in administrative proceedings, the ontological inequality of the parties with regard to evidence forms the basis of the so-called dispositive principle with an acquisitive method, according to which the Court can make up for evidentiary deficiencies resulting from the Administration's greater proximity to the evidence, but this This general rule certainly cannot overturn the fundamental principle that a person bringing a legal action must clearly indicate the subject matter of their claim. The Court believes that the possibility of the judge exercising ex officio investigative powers should be admitted, in theory, but that this prerogative must constitute a last resort. In any case, it remains firm that, even when the facts are not fully available to the appellant, the judge should never use his powers to investigate the true intention of the party beyond what is explicitly stated in the legal action, essentially replacing it and compromising the principle of absolute impartiality of the adjudicating body with respect to the interests at stake. The principle of dispositive action with the acquisitive method "cannot, however, ever be reduced to an absolute and general reversal of the burden of proof and, in any case, does not allow the administrative judge to substitute himself for the burdened party when the appellant is unable to prove the fact forming the basis of his action." (Regional Administrative Court of Campania, Section VI, July 15, 2014, No. 3962; State Council, Section V, November 10, 2010, No. 8006)" (Regional Administrative Court of Lazio-Rome, Section I bis, Ruling, June 24, 2015, No. 8639).

It was also noted that, by virtue of the provisions of Article 5 of the Regulation and the principle of accountability, the data controller is extremely free to choose the methods and means to meet the obligations arising from the applicable legislation on the protection of personal data. Consequently, this discretion also affects the means and methods chosen to fulfill the burden of proof, which in this case required the identification of consent-gaining techniques based on the principles of unequivocality, unchangeability, and certainty, thus capable of overcoming any disputes. of the interested party.

1.4.     Notification of violations

The Office, following the investigation, adopted the aforementioned notice of complaint no. 36361/26, in which, first of all, it observed that the promotional activities carried out by Nuova Corrente towards the complainant appeared to have been carried out without an adequate legal basis and, consequently, in violation of Articles 5, 6, and 7 of the Regulation and Article 130 of the Code.

Furthermore, the conduct just referred to also appeared to be particularly serious, since, according to the Company's statements, it had affected at least nine other interested parties.

From another and different perspective, the Office noted that Nuova Corrente appeared not to have yet fully assimilated the obligations arising from the principle of accountability, with particular regard to the lawfulness of the entire processing chain from contact to contract, nor the duties arising from the provisions of Article 28 of the Regulation.
Finally, it was noted that the case at hand also appeared to demonstrate a violation of Articles 12 and 15 to 22 of the Regulation regarding the exercise of data subjects' rights.

The Office therefore charged Nuova Corrente with the following violations:

- Articles 5, 6, and 7 of the Regulation, as well as Article 130 of the Code, for having carried out the above-described processing of personal data without an appropriate legal basis;

- Articles 5, 24, and 28 of the Regulation, for having carried out the above-described processing of personal data in violation of the duties arising from the principle of accountability and Article 28 of the Regulation;

- Articles 12 and 15 to 22 of the Regulation for failing to respond to the request to exercise rights submitted by the complainant and, more generally, for failing to adopt appropriate measures to ensure the adequate management of requests to exercise rights. by interested parties.

2. THE OWNER'S DEFENSE

In a letter dated April 8, 2026 (see Prot. No. 54361 of April 9, 2026), Nuova Corrente preliminarily emphasized that it had no involvement in any alleged fraudulent and/or deceptive conduct against the complainant, as was also evident from the internal operator's demeanor during the verification call. In this regard, the Company stated that, given the concerns expressed by the user and the lack of a clear interest in concluding the contract, the operator had immediately acknowledged the interested party's disinterest, interrupted the contract activation process, and rejected the agency's contractual proposal. According to Nuova Corrente's defense, this conduct demonstrated that the direct contact phase—not even mandatory under industry regulations—was not merely intended to automatically confirm the offer, but rather constituted "a concrete safeguard aimed at ensuring customer awareness and preventing unwanted activations."

On the same occasion, the Company emphasized that the existing agency agreement imposed on Joseph Agency "the obligation to present Nuova Corrente's Services to Customers in a manner consistent with their actual characteristics, as indicated and described in the Offer, and to keep up to date with the Offer," adhering to the provided call script, and that it was prohibited "to make inaccurate, misleading, and/or denigrating statements regarding the Services, and other products and/or services, including those of third parties." The use of the script was also referred to in the appointment as data processor, and the contract prohibited any changes to the scripts and summary documentation prepared by the Principal. This script also stipulated that Joseph Agency would request the supply data (POD and PDR), while Nuova Corrente would request the banking data for the purposes of finalizing the contract. The agency agreement also provided for a "sanctioning mechanism, in the form of a penalty and non-payment of commission, as well as reimbursement of costs and damages, for each result of the audits conducted by the principal and/or for each complaint received from Clients and/or potential Clients attributable to the activity under the same agreement, which revealed violations of criminal, civil, or administrative laws and/or contractual obligations."

Nuova Corrente further emphasized that the notice of termination of the relationship with Joseph Agency S.r.l.s. The decision was based on the lack of commercial production for purely prudent reasons, since "objective and documentary evidence capable of conclusively proving any conduct by the partner that did not comply with the contractual provisions was not yet available," although this decision was also prompted by the complainant's report, as a measure to immediately mitigate the alleged critical issues.

Regarding the alleged inadequacy of the controls over the supplier's operations, Nuova Corrente stated that the relationship with Joseph Agency S.r.l.s. had lasted approximately three and a half months and that no other irregularities had been recorded prior to that. Therefore, the absence of audits, even though they were planned, was attributable to the short duration of the collaboration and the partner's reduced productivity.

Regarding the unsuitable legal basis for processing the complainant's data, the Company emphasized that the collection of personal data and consent from potential customers had been carried out by Joseph Agency S.r.l.s. Using a third party, Clean Energy Consulting, whose name and role had never been disclosed to Nuova Corrente, in violation of the provisions of the appointment as data controller, thus hindering Nuova Corrente's supervisory activity.

This lack of transparency also resulted in contradictory statements provided during the proceedings regarding the origin of the data.

Regarding the failure to respond to the complainant's request to exercise her rights, Nuova Corrente argued that the request had been "managed and processed from an exclusively commercial perspective"; that it had not caused irreparable harm to the interested party; and that it was an isolated incident resulting from the fact that the request had been sent to the Company's certified email address and not to the email address dedicated to handling requests regarding personal data protection, as indicated in the privacy policy published on the Company's website. To prevent similar critical issues from recurring, Nuova Corrente had already integrated the management of requests for the exercise of privacy rights into its Ticketing/CRM system during the course of the proceedings. As a result, "each request received is now recorded with a 'Privacy Ticket' associated with a 30-day countdown. The system prevents the case from being closed until proof of the response sent to the interested party is uploaded, making it impossible to omit the request due to forgetfulness or carelessness."

Nuova Corrente also stated that it had initiated a plan to strengthen its organizational structure and compliance controls through "the adoption of structured lead provider qualification and selection procedures, based on criteria for traceability and verifiability of sources; the introduction of advanced proof of consent systems (including double opt-in or equivalent mechanisms). The Company has planned to implement a telephone double opt-in protocol via Strong Authentication (SMS OTP). This system requires that consent (or the contract) be finalized by entering a unique code sent in real time to the data subject's mobile device. The procedure will ensure the electronic traceability of the user's consent, uniquely associating the validation timestamp with the contacted user (...); comprehensive review of data processor appointments pursuant to Article 28 of the GDPR; implementation of periodic audits and documented checks on partners; implementation of commercial scripts from the perspective of transparency and fairness.

In addition, the Company expressed its willingness to adhere to the Code of Conduct for Telemarketing and Teleselling, "establishing as a privileged selection criterion for its partnerships that Agencies adhere to the same Code."

Finally, Nuova Corrente cited the mitigating circumstances recurring in this case and requested their application for the purposes of determining a possible financial penalty.

3. AUTHORITY'S ASSESSMENTS

First, it is noted that Nuova Corrente's observations, provided during the proceedings, do not appear to be sufficient to exclude the Company's liability for the alleged violations.

The promotional activities carried out by Nuova Corrente towards the complainant appear to have been carried out without an appropriate legal basis and, consequently, in violation of Articles 5, 6, and 7 of the Regulation and Article 130 of the Code.

In fact, despite the burden of proof falling on the data controller pursuant to Articles 5 and 24 of the Regulation, the clarifications provided do not appear adequate to explain the origin of the data subject's data, nor to demonstrate the existence of an appropriate legal basis for the processing, given that the Company has provided contradictory information on this point, not even supported by sufficient evidence.

Regarding the origin of the data, the Company initially stated that it was acquired through a form published on the website offertegratis.com, which was traced back to a Bulgarian company. Subsequently, Nuova Corrente stated that the complainant's personal data had also been acquired through social networks. The statements regarding the timing of the consent acquisition also appear contradictory. Furthermore, both of the aforementioned data collection sources are unable to explain why the calling operator, during the initial contact complained of, was also in possession of supply and banking data, as reported by the interested party pursuant to Article 168 of the Code and never disputed by the Company. This type of data is not among those requested on the offertegratis.com website, nor is it included in the Excel file detailing the ten personal data provided by Joseph Agency S.r.l.s.

More specifically, with respect to the offertegratis.com website, which is owned by the Bulgarian company Clean Energy Consulting, it should be noted that the formulas at the bottom of the form are not suitable for obtaining valid consent pursuant to Articles 4, point 11, and 7 of the Regulation, as they present multiple critical elements.

At first glance, in fact, the formulas used for the transfer of data to third parties for promotional purposes appear to overlap (i.e., second and third consent), with the sole difference that only the second form contains the link apparently useful for making a differentiated choice based on product categories. Secondly, the complete list of third parties placed next to the flags differentiated by the transferee's product category is always the same (see second consent). The same list can also be accessed via the link within the third consent form. In other words, this form structure makes it difficult to determine whether granting the second and third consents, regardless of the choice of individual categories, entails the transfer of personal data without distinction to all the numerous transferees listed therein. Furthermore, even the sole provision of the third consent entails the transfer of personal data without distinction to all operators belonging to the numerous and diverse product categories indicated therein, without the data subject's ability to make a free, specific, and granular choice, resulting in a loss of control over their personal information.

The principle that the use of formulas lacking transparency and/or that do not allow for free, specific, and granular consent is in direct conflict with current legislation on the protection of personal data; this has, moreover, been repeatedly reiterated by the Authority also in its most recent resolutions (see Provision no. 114 of 27 February 2025, available for consultation on the website www.gpdp.it, web doc. no. 10114967, where it is stated that «Due to the broad wording used in relation to the large and indistinct group of transferees of personal data operating in very different sectors, in fact, the interested party who wishes to receive offers relating to one or more of the product categories indicated therein or wishes to receive them through only one of the channels indicated is, in fact, forced to give a single consent to the indiscriminate transfer of his/her data to all, without distinction, third party recipients for promotional purposes and is not placed in a position to easily exercise the rights recognised by the current legislation (…) The use of such broad and specific formulas for the acquisition of consent to the processing of personal data for the transfer to third parties for marketing purposes Generic, which does not allow the data subject to express a granular and differentiated will, for example in relation to the product category of the commercial offers they wish to receive (i.e., telephony, energy supplies, insurance services, fashion, cars, etc.) or which, due to the specific configuration of the forms and information used, does not allow them to easily express their wishes regarding the tools through which promotional communications are conveyed, does not allow for the acquisition of a valid, informed, and unequivocal expression of will from the data subject, since it ends up resulting in the uncontrollable dissemination of personal data to an indiscriminate audience of operators, also undermining the possibility of effectively exercising the rights recognized by law in favor of data subjects.

In other words, the expression of will regarding the transfer of data to third parties for marketing purposes can be considered truly free only if the data subject is guaranteed an effective choice and control over his or her personal data (see Guidelines no. 5/2020 on consent pursuant to Regulation (EU) 2016/679, available for consultation on the website www.edpb.europa.eu, paragraph 3.1 "The element of 'free' expression of will implies that the data subject has an effective choice and control over his or her data. As a general rule, the Regulation establishes that if the data subject does not have an effective choice or feels obliged to consent or will suffer negative consequences if he or she does not consent, the consent will not be valid. If consent is a non-negotiable element of the general terms and conditions of a contract/service, it is presumed that it was not given freely. Consequently, consent will not be considered free if the data subject cannot refuse or withdraw it without suffering detriment. The General Data Protection Regulation "The Data Protection Authority (DPA) also took into account the notion of imbalance between the controller and the data subject" and paragraph 3.1.3 "If the controller has combined different processing purposes and has not requested separate consent for each of them, there is no freedom. Granularity is closely related to the need for specific consent, as analyzed in section 3.2. When data processing is aimed at pursuing different purposes, the solution to satisfying the conditions for valid consent lies in granularity, i.e., the separation of purposes and obtaining consent for each of them.").

On this point, it is also noted that Nuova Corrente's claims regarding the origin of the complainant's data do not even appear to be supported by sufficient evidence and, in any case, have been repeatedly contested by the applicant, who, in making declarations pursuant to Article 168 of the Code, denied having consulted the referenced websites and provided his personal data.

Regarding the offertegratis.com website, the Company had only provided a declaration issued by the list provider containing the timestamps, IP address, and personal data of the complainant, which, however, lacked the requirements of certainty, unequivocality, and unalterability.

Similarly, even with respect to the personal data acquired via social networks, the evidence provided by the Company appears to lack the aforementioned requirements and, as a result, does not allow the objections raised by the interested party to be refuted. Nuova Corrente merely produced an Excel file and an invoice issued by Meta Platforms, Inc. to Joseph Agency S.r.l.s., relating to "Promoting the My Fibra Module" campaigns, but this documentation lacks any reference to Nuova Corrente or the promotion of energy services.

The consent acquisition systems used on the offertegratis.com portal and on social networks, in fact, do not appear to be adequately equipped with measures to verify the identity of the person entering personal data in the form and, therefore, to unequivocally prove that consent has been given.

The Authority has also repeatedly highlighted the inadequacy of consent acquisition systems lacking any measures to verify the identity of the person entering personal data in the form (such as (e.g., double opt-in), noting that such mechanisms do not allow for the association of those expressions of will with sufficient certainty with the data subjects and, therefore, the burden of proof on the data controller regarding the acquisition of valid consent from the data subject to be deemed fulfilled. Similarly, in the absence of a control system, adequate measures to ensure that the processing of personal data is carried out in full compliance with the principle of accuracy of processing do not appear to be implemented.

It should be added that these findings are even more stringent when considered in the current socio-economic and technological context, characterized by the spread of non-navigable websites featuring only contact collection forms, used for the sole purpose of giving a semblance of lawfulness to contact lists acquired outside of the legal requirements.

The Authority recently examined this issue in depth with Provision No. 330 of June 4, 2025, web doc No. 10143278, ruling that Furthermore, with regard to the lack of an express regulatory requirement to qualify consent as a double opt-in, it is noted that—contrary to what the NCA maintains—one of the requirements for lawful consent under Article 7 of the Regulation includes the obligation for the data controller to demonstrate that the data subject has given his or her consent. This demonstration, although it is now known in the current state of the art, cannot be considered sufficiently demonstrated by the presentation of stamps—qualified as log files—containing data often unknown to the data subjects, lacking the IT requirements of unalterability, and concerning lists consisting of subjects, often located outside the EU, who do not offer adequate guarantees. In this context, it must first be taken into account that the Regulation does not expressly provide specific regulatory obligations for individual cases but requires compliance with general principles that must be adapted to the context, potential risks, and expectations of the data subjects. Starting from this assumption, the Garante has repeatedly provided guidance on specific cases, recalling that the documentation of consent in a double opt-in manner is essential. Double opt-in is a form of consent documentation that offers greater guarantees and can be considered, given the current state of the art, a minimum protection measure for the data subject but also for the data controller, who is required to demonstrate the lawfulness of the processing (see, for example, www.garanteprivacy.it, provision of December 15, 2022, web doc 9852290, provision of October 26, 2017, web doc no. 7320903, and provision of November 25, 2021, web doc no. 9737185); similar methods of consent documentation are also indicated in the Code of Conduct for Telemarketing and Teleselling (provision of March 7, 2024, web doc no. 9993808).

Provision no. 574 of May 9, 2024, available for consultation on the website www.gpdp.it, web doc. n. 10107938, the Authority observed that the choice to "implement the described procedure of sending an SMS to allow the data subject to revoke their availability for recontact does not appear to be functional to discourage the possible use of bots that, massively, can enter telephone numbers to be recontacted, given that the two-minute limit within which the data subject can exercise such reconsideration is clearly not suitable to protect those who have been unknowingly entered into the recontact mechanism and who find themselves receiving a mysterious SMS in which, moreover, it is suggested to activate a link (a practice widely discouraged to avoid introducing malware into one's devices). More effective, in this sense, seems to be a "confirmation" procedure of consent to recontact (by clicking a specific link or entering an OTP sent via SMS in the web form) without which the recontact itself would not take place."

Considering the numerous and detailed indications provided by the Authority on the matter, Nuova Corrente, in its capacity as data controller and in fulfilling its duties, including those deriving from the principle of accountability, could and should have realized that this source of personal data, which was also used for the purposes of carrying out promotional activities in its interest and from which it derived financial benefit, was in open violation of the provisions in force regarding the protection of personal data and of the Authority's most recent arrests.

In this regard, the Company's representation regarding the lack of awareness of Clean Energy Consulting's role cannot be considered mitigating or exculpatory, given that both the contract signed with Joseph Agency and the attached appointment as data processor contained reference to the possibility of using other parties and collaborators in fulfilling the mandate conferred. It should be added that the conduct described above also appears to be particularly serious, given that, by the Company's own admission, it involved at least nine other interested parties.

More In general, Nuova Corrente appears not to have fully assimilated the obligations arising from the principle of accountability, with particular regard to the lawfulness of the entire processing chain from contact to contract, nor the duties arising from the provisions of Article 28 of the Regulation.

On the first level, the Company appears to have completely delegated the choice of data procurement methods to the agency, without having bothered to identify upstream selection criteria or carry out effective downstream checks. In this regard, mere references to the lawful origin of the lists or contractual obligations cannot be considered sufficient. Nor is there any evidence in the proceedings regarding the implementation of the aforementioned random and periodic checks.

Article 138, paragraph 1, of Legislative Decree no. 5 of the Code of Conduct on telemarketing and teleselling (see Provision no. 70 of 9 March 2023, web doc. no. 9868813 and Provision no. 148 of 7 March 2024, web doc. no. 9993808), which, regardless of actual compliance, takes on the value of best practices in the sector, in the part in which it clarifies that «Without prejudice to the division of responsibilities and the provisions of the previous article 4 regarding joint liability, the data controller guarantees and requires its data processors that the processing, starting from the data collection phase, takes place in compliance with the Regulation, the Code and this Code of Conduct. To this end, the data controller shall adopt appropriate measures to verify that the data processor complies with the instructions given, through audit mechanisms such as "teaser numbers" (own numbers within the list of contactable numbers) and random checks on contracts entered into, to verify that contacts are made in accordance with the methods established by the data controller and in compliance with Articles 6 and 11 of this Code of Conduct and that, in particular, the information has been provided in an intelligible manner.

In this regard, the Company observed that the lack of controls over Joseph Agency was caused by the short duration of the contractual relationship. However, this objection cannot be upheld given that Nuova Corrente has not provided any evidence—not even documentary evidence—to prove that such activities were planned and systematically carried out within its corporate structure, for example, through the formalization of an ad hoc procedure or the implementation of controls on other business partners.

Likewise, with regard to the relationship with Joseph Agency S.r.l.s., the evidence emerging during the proceedings has established that conduct contrary to the provisions of Article 28 of the Regulation (so-called culpa in eligendo and culpa in vigilando) had occurred.

First, the forms used to appoint the data controller—which were not even properly completed—refer to provisions that have now been repealed.

Although Article 28 of the Regulation requires the use of partners with adequate privacy expertise, the criteria cited for pre-qualification of suppliers (i.e., being an Italian company duly registered in the Register of Communications and Postal Operators) have little to do with the protection of personal data, as they relate instead to financial solvency and the required communications qualifications.

Furthermore, the proceedings do not even provide evidence that relevant instructions were issued regarding the execution of promotional contacts, nor that adequate controls were carried out on the data controller's actions.

This is supported by the telephone operator's fraudulent and deceptive conduct during the first of the contacts at issue, as described by the complainant and corroborated by the recording of the second call. Similarly, the termination of the contract signed with the agency makes no reference to the violation of personal data protection legislation and, in any case, was carried out before the complaint was filed with the Authority.

Finally, it is noted that the events in this case also demonstrate a violation of Articles 12 and 15 to 22 of the Regulation regarding the exercise of data subjects' rights.

Indeed, despite the burden of proof falling on the data controller, the Company has in no way demonstrated that, prior to the initiation of today's proceedings, adequate measures had been implemented to ensure the adequate management of requests to exercise rights. Nor, with regard to today's complainant, has Nuova Corrente offered any valid excuse for its failure to respond to her duly submitted request.

In this regard, the Company argued that the request had been "managed and processed from an exclusively commercial perspective," but this argument is not persuasive given that the subject and body of the request made express and unequivocal reference to personal data protection legislation, while no commercial prerogative or right of withdrawal was mentioned. The objection that the request was sent to the Company's certified email address and not to the email address dedicated to managing requests regarding personal data protection is also irrelevant, since current legislation does not impose any specific formalities on this point. Therefore, the data controller is required to respond to requests regarding rights, regardless of the channel and form used, unless any of the circumstances set out in Article 12, paragraph 5, of the Regulation apply or the exclusions provided for in relation to the individual rights granted to the data subjects exist.

In this context, while appreciating the corrective measures already spontaneously implemented during the proceedings and those to be adopted shortly, Nuova Corrente's liability for the alleged violations must be definitively confirmed.

4. CONCLUSIONS

Based on the above, Nuova Corrente's liability for the following violations is deemed established:

- Articles 5, 6, and 7 of the Regulation, as well as Article 12, paragraph 5, of the Regulation. 130 of the Code, for having carried out the above-described processing of personal data without an appropriate legal basis;

- Articles 5, 24, and 28 of the Regulation, for having carried out the above-described processing of personal data in violation of the duties arising from the principle of accountability and Article 28 of the Regulation;

- Articles 12 and 15 to 22 of the Regulation for failing to respond to the request to exercise their rights submitted by the complainant and, more generally, for failing to adopt appropriate measures to ensure the adequate management of requests to exercise their rights by data subjects.

Having also established the unlawfulness of the Company's conduct with regard to the processing in question, it is necessary to issue an injunction pursuant to Articles 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, for the application against Nuova Corrente of the administrative pecuniary sanction provided for by Article 83, paragraphs 3 and 5, of the Regulation.

5. INJUNCTION ORDER FOR THE APPLICATION OF THE ADMINISTRATIVE PECUNIARY SANCTION

The above violations require the adoption of an injunction order, pursuant to Articles 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, for the application against Nuova Corrente of the administrative pecuniary sanction provided for by Article 83, paragraphs 3 and 5, of the Regulation.

More specifically, pursuant to Article 83, paragraph 3 of the Regulation "If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement". Pursuant to the following paragraph 5 "(...) infringement of the following provisions shall be subject to administrative fines up to 20 million euros, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including the conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the rights of data subjects pursuant to Articles 12 to 22; (c) transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligation under the laws of the Member States adopted pursuant to Chapter IX; (e) failure to comply with an order, a temporary or definitive limitation of processing, or an order to suspend data flows issued by the supervisory authority pursuant to Article 58(2), or denial of access in violation of Article 58(1).

Since in this case, a violation of Articles 5, 6, 7, 12, 15 to 22, 24, and 28 of the Regulation, as well as Article 130 of the Code, has been established, the provisions of Article 83, paragraphs 3 and 5 of the Regulation apply. Furthermore, reference must also be made to Nuova Corrente's turnover, as derived from the financial and tax information acquired. Therefore, in this case, the maximum fine set forth in Article 83, paragraphs 3 and 5 of the Regulation is €20,000,000.00.

To determine the amount of the fine, the factors indicated in Article 83, paragraph 2, of the Regulation must be taken into account.

In this case, the following are relevant:

1) the seriousness of the violations (Article 83, paragraph 2, letter a) of the Regulation), taking into account the object and purpose of the data processed, which can be traced back to the overall phenomenon of telemarketing. The Authority has adopted numerous measures, particularly over the last five years, that have fully examined the many critical factors, providing data controllers with extensive guidance on how to adapt processing to current legislation and mitigate the impact of nuisance calls on data subjects;

2) as a mitigating factor (Article 83, paragraph 2, letter f) of the Regulation), the degree of cooperation with the Supervisory Authority in addressing the violations;

3) as a further mitigating factor (Article 83, paragraph 2, letter g) of the Regulation), the categories of personal data affected by the breach (i.e., common data).

Based on all of the above factors, and on the principles of effectiveness, proportionality, and dissuasiveness set forth in Article 83, paragraph 1, of the Regulation, and taking into account the necessary balance between data subjects' rights and freedom to conduct a business, also to limit the financial impact of the fine on the Company's organizational and functional needs, it is believed that Nuova Corrente should be subject to an administrative fine of €15,000.00, equal to 0.075% of the maximum statutory fine.

In this case, it is believed that the additional sanction of publication of this provision on the Garante's website, as provided for by Article 166, paragraph 7 of the Code and Article 16 of the Garante's Regulation No. 1/2019, should be applied, taking into account the nature of the Company's processing and conduct, as well as the risks to the rights and freedoms of data subjects.
Pursuant to the principles set forth in Article 83 of the Regulation, the imposition of this additional sanction appears reasonable and proportionate given the particular negative value of the conduct being criticized, especially given its seriousness, as it pertains to the fundamental—and consistently reiterated—principles of personal data protection legislation.

Finally, the conditions set forth in Article 17 of Regulation No. 1/2019 concerning internal procedures of external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Garante, are met.

NOW, THEREFORE, THE GUARANTOR

pursuant to Article 57, paragraph 1, letter a), of the Regulation, declares the processing carried out by Nuova Corrente S.r.l., with registered office in Vibo Valentia (VV), Via Spogliatore, S.N.C., VAT No. 12126890966, to be unlawful, within the terms set out in the reasons for the decision;

ORDERS

Nuova Corrente S.r.l., represented by its legal representative pro tempore, with registered office in Vibo Valentia (VV), Via Spogliatore, S.N.C., VAT No. 12126890966, to pay the sum of €15,000.00 (fifteen thousand/00) as an administrative fine for the violations indicated in the reasons for the decision, stating that the offender, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by complying with the provisions set forth and paying, within thirty days, an amount equal to half the fine imposed.

ORDERS

the aforementioned Company, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of €15,000.00 (fifteen thousand/00), according to the procedures indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the consequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981.

ORDERS

a) the publication of this order, pursuant to Articles 154-bis of the Code and 37 of Regulation No. 1/2019;

b) the application of the additional sanction of publication of this injunction on the Authority's website, as provided for by Articles 166, paragraph 7, of the Code and 16 of the Authority's Regulation No. 1/2019;

c) the recording of this provision in the Authority's internal register—provided for by Article 57, paragraph 1, letter u), of the Regulation, as well as Article 17 of Regulation No. 1/2019 concerning internal procedures of external relevance, aimed at carrying out the tasks and exercising the powers delegated to the Authority—relating to violations and measures adopted in accordance with Article 58, paragraph 2, of the Regulation itself.

Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 1 of September 1, 2011, 150, an appeal against this provision may be lodged with the ordinary judicial authority, with an appeal filed with the ordinary court of the place where the data controller resides, or, alternatively, with the court of the place of residence of the interested party, within thirty days from the date of notification of the provision itself, or sixty days if the appellant resides abroad.

Rome, April 29, 2026

THE PRESIDENT
Stanzione

THE REPORTER
Stanzione

THE SECRETARY GENERAL
Montuori