Garante per la protezione dei dati personali (Italy) - 556/2026

From GDPRhub
Garante per la protezione dei dati personali - 556/2026
Authority: Garante per la protezione dei dati personali (Italy)
Jurisdiction: Italy
Relevant Law: Article 5(2) GDPR
Article 24 GDPR
Article 28 GDPR
Article 5(1) GDPR
Article 6 GDPR
Article 7 GDPR
Article 25 GDPR
Article 32 GDPR
Article 12(2) GDPR
Article 12(3) GDPR
Article 130 of the Codice in Materia di Protezione dei Dati Personali
Type: Investigation
Outcome: Violation Found
Started:
Decided: 23.07.2026
Published:
Fine: 9516000.0 EUR
Parties: TIM S.p.A.
National Case Number/Name: 556/2026
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Italian
Original Source: GPDP (in IT)
Initial Contributor: ds

The DPA fined a telecom provider €9,516,000 for unlawful telemarketing, inadequate supervision of its sales partners and failures in handling data subject rights.

English Summary

Facts

Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited promotional calls made on behalf of the controller, often to telephone numbers registered in the Public Opt-Out Registry.

The investigation revealed that users initially received unsolicited promotional calls from untraceable or spoofed numbers offering the controller’s services. They subsequently received, via SMS or messaging services, a link to an online form which they were invited to complete in order to generate what appeared to be a spontaneous request for a callback, a so-called “Lead”. This was followed by another call from the call centre, this time using a formally registered number.

According to the DPA, this procedure was used to conceal the unlawful origin of the initial contact. The controller’s partners presented the Leads as spontaneous requests from users, although they had actually been generated following previous promotional calls made without consent. Orders and activation requests resulting from those contacts were subsequently entered into the controller’s official systems.

The DPA also identified significant discrepancies between the number of Leads reported by certain partners and the number of calls they made. In some cases, the number of contacts substantially exceeded the number of declared Leads, while conversion rates were particularly low. The DPA stated that such anomalies should have triggered internal checks, automated alerts and, where appropriate, the immediate suspension of the relevant data flows.

The DPA found that the controller’s systems also lacked mechanisms to verify whether the person entering a telephone number into a Lead form was actually the holder of that number. During the investigation, the controller introduced an SMS-based opt-out mechanism under which the number holder had five minutes to reject the callback or withdraw consent. It also introduced measures to monitor IP addresses and restrict bulk submissions of telephone numbers.

The investigation further identified problems concerning the exercise of data subject rights. In several cases, users continued to receive promotional communications for months after objecting. Procedures for withdrawing consent or opting out of marketing required users to log into their MyTIM account or use dedicated applications, while requests concerning access, erasure and objection were answered late, incompletely or not at all.

The controller argued that the unlawful calls had been made by unknown third parties using numbers outside its official sales network and in breach of its instructions. It also maintained that the Leads appeared formally valid in its systems, that none of the cases examined resulted in the final conclusion of a contract and that its governance framework complied with the Code of Conduct for telemarketing.


Holding

The DPA held that adherence to a code of conduct was not, in itself, sufficient to demonstrate compliance with the GDPR. It stated that the controller had to demonstrate that the measures adopted were sufficiently implemented and effective in practice.

It further held that the controller’s liability arose from its own failures in selecting, supervising and monitoring its partners and from the inadequate organisational and technical design of the systems through which Leads and activation orders were accepted. The DPA found that the controller breached Article 5(2) GDPR by failing to adopt and demonstrate adequate systems for monitoring its sales network. It also held that the broader organisational shortcomings concerning processing carried out through commercial partners infringed Article 24 GDPR and Article 28 GDPR.

The DPA stated that the unlawful telemarketing “underworld” was a known and systemic risk of the sector rather than an unforeseeable event. Since the controller outsourced promotional activities to third parties and benefited economically from the contacts generated, it held that the controller was required to exercise active and ongoing oversight over the entire sales chain.

Furthermore, the DPA held that the controller could not simply rely on the formal validity of the Leads recorded in its systems. The Leads at issue had been generated following unsolicited and deceptive calls and could therefore not be regarded as spontaneous, freely given and informed requests by users. It stated that neither subsequent consent nor the later conclusion of a contract could retroactively legitimise the initial unlawful collection and use of personal data. The DPA therefore found that the controller had carried out or allowed promotional contacts without valid, prior and specific consent, in breach of Article 5(1) GDPR, Article 6 GDPR, Article 7 GDPR and Article 130 of the Italian Data Protection Code.

The DPA also held that the controller’s SMS-based opt-out mechanism was inadequate. Requiring a person whose telephone number had been entered into the system by a third party to react within five minutes reversed the lawful model of consent. It stated that silence or inactivity could not amount to consent, nor could an unsuspecting user be required to take action to prevent processing which they had never requested. The DPA considered a preventive opt-in mechanism, such as verification of the telephone number through a one-time password, an appropriate means of addressing this risk. It found that the inadequate design of the processing and the failure to implement appropriate safeguards from the outset infringed Article 25 GDPR. The DPA further found that the insufficient security measures concerning consent-collection flows and the systems used to upload activation orders infringed Article 32 GDPR.

Regarding data subject rights, the DPA held that withdrawing consent must be as easy as giving it. It stated that requiring users to log into an account, use an application or complete complex technical steps imposed disproportionate obstacles, particularly on individuals who were not customers of the controller. The DPA found that these shortcomings infringed Article 12(2) GDPR, Article 24 GDPR and the rights of the data subjects. It further found an infringement of Article 12(3) GDPR in relation to requests that were not answered or were answered with unjustified delay.

The DPA ordered the controller to amend its procedures for generating Leads and callbacks and to ensure that consent to be contacted could be shown to originate from the actual holder of the number. It also ordered the controller to strengthen its supervision of commercial partners and improve its procedures for handling the exercise of data subject rights.

Finally, the DPA imposed a fine of €9,516,000 on the controller. It took into account as a mitigating factor the controller’s adherence to the Code of Conduct for telemarketing.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.

SEE ALSO Press Release of July 31, 2026

[Web Doc. No. 10277005]

Decision of July 23, 2026

Register of Decisions
No. 556 of July 23, 2026

THE DATA PROTECTION AUTHORITY

AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”);

HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003, hereinafter the “Code”);

HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”);

HAVING REGARD TO the documentation on file;

HAVING REGARD TO the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801);

RAPPORTEUR: Prof. Pasquale Stanzione;

1. FACTS AND PRELIMINARY INVESTIGATION CONDUCTED

1.1. Origin of the preliminary investigation

The Authority, in exercising the powers set forth in Articles 157 and 158 of the Code, initiated an inspection of TIM S.p.A. (hereinafter “TIM,” the “Company” or the “Data Controller”), in collaboration with the Special Unit for Privacy Protection and Technological Fraud of the Guardia di Finanza, following the receipt of numerous complaints and reports, including those submitted by a correspondent for a well-known television program.

In a nutshell, the reports highlighted a phenomenon already known to the Authority, characterized by the activities of fraudulent call centers that make promotional calls on behalf of TIM using phone numbers outside the Company’s official sales network. This conduct is aimed at the unlawful collection of users’ personal data; users, under the mistaken belief that they are speaking with an authorized TIM agent, provide this information and sometimes sign up for promotional offers.

Specifically, among the operational schemes recently implemented by these agencies and reported by complainants is the following:

a) Receipt of unsolicited calls on phone numbers duly registered with the Public Do Not Call Registry (hereinafter “RPO”) from telephone operators who, using caller ID spoofing techniques, propose the activation of TIM offers or services;

b) sending data subjects, via SMS, a hyperlink to a webpage of an official partner in the TIM sales network, containing a form that the User is invited to fill out to submit an independent request for a callback (a so-called “Lead”);

c) subsequent contact with the data subject—based on the (fictitious) request generated via the web—by the call center, this time using a phone number duly registered in the Register of Communications Operators (hereinafter “ROC”), in order to generate an apparently legitimate flow of calls and a formally compliant contract formation process.

1.2. Preliminary Investigation Conducted

Based on the information provided in the reports, and in parallel with the investigations conducted in relation to other reports and complaints, the Office requested that TIM provide information necessary to obtain a complete picture of the various critical issues identified by the reporters and complainants.

Through the inspection and preliminary investigation conducted regarding the Company, it was possible to obtain a significant amount of information and documents, which were made available to the Authority by the Guardia di Finanza via letters dated March 26 and 27, 2025, Ref. No. 442/25, and subsequently supplemented by notes Ref. No. 54010 dated April 18, 2025, Ref. No. 55188 dated April 23, 2025, Ref. No. 95514 dated July 7, 2025, Ref. No. 108311 dated August 4, 2025, and, most recently, Ref. No. 174524 dated December 16, 2025.

2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND PENALTY MEASURES

2.1. Findings of the Preliminary Investigation and Initiation of Proceedings

Based on the evidence gathered during the activities described above, by a notice dated February 9, 2026 (Ref. No. 18734), served in accordance with Article 166, paragraph 5, of the Code and reproduced in full herein, the Office initiated proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation against the controller, inviting the latter to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The alleged violations are detailed below.

2.1.1. Verification procedures regarding lead forms collected by digital agencies or on the TIM website—ex officio finding

During the inspection, initiated ex officio against TIM, certain critical issues emerged regarding the procedures for acquiring personal data (so-called “leads”) collected through partner digital agencies or directly from the Data Controller’s website. In particular, there was a complete lack of mechanisms to verify the actual ownership of the phone numbers provided in the online data collection forms, thereby exposing data subjects to the risk of unsolicited contact.

In order to remedy the irregularities identified and in accordance with the principle of accountability (pursuant to Article 5, para 2, of the Regulation), during the course of the investigation—through submissions filed in the months following the inspection— the Company stated that it had implemented an automated preventive verification system, based on an M2M integration with the central TIMCO system.

Specifically, the new procedural framework is based on an opt-out mechanism via SMS: upon entry of the lead, the data subject receives a notification message and has a 5-minute window to deny ownership of the contact information or revoke consent (the so-called “right to change one’s mind”). TIM has also adopted additional technical and organizational measures to protect data subjects, including: (i) anti-phishing measures: implementation of communications sent exclusively via certified aliases and transparent URLs that can be uniquely traced back to the Data Controller’s official domain; and (ii) anti-fraud systems (IP control): the introduction of an automated blocking system designed to prevent the submission of multiple requests from the same IP address within a 15-minute time interval, specifically aimed at neutralizing and countering the mass upload of personal data via computer applications (so-called “bots”).

With regard to the system’s operational effectiveness and the progress of the aforementioned infrastructure, the Data Controller submitted additional documentation (Ref. No. 174524 dated December 16, 2025) certifying that the system had undergone final testing, with the full and final rollout scheduled for January 31, 2026.

While the Office views the Data Controller’s efforts to comply favorably, it has nevertheless notified the Company of an alleged violation of Article 25, para 1, of the Regulation, for failing to adopt adequate technical and organizational measures to ensure, from the design stage onward (“Data Protection by Design”), that processing was carried out in accordance with the principles of the legislation at every stage.

With specific regard to the aforementioned opt-out measure, the Office deemed it structurally unsuitable for protecting individuals whose phone numbers are entered into forms without their knowledge. In fact, these individuals receive an unsolicited text message containing an invitation to click a link to block future contacts; in this context, a procedure requiring prior confirmation of consent to be contacted again (opt-in) appears to be more appropriate.

During the year 2025, the Authority received numerous reports and complaints (approximately 7,000 complaints) concerning the receipt of unsolicited and unauthorized promotional communications on behalf of TIM. Some of these reports, which were initially the subject of separate investigations, were subsequently consolidated into a single main proceeding for the purpose of unified handling, given the evident systemic and structural nature of the alleged conduct.

A first and substantial group of complaints relates directly to TIM’s overall management of its data assets. The inspection and the findings of the preliminary investigation revealed that the Company, despite having made efforts and invested financial and organizational resources to combat the phenomenon of so-called “unknown calls,” it implemented control systems across the entire data collection “chain” that proved to be entirely unsuitable and deficient in many respects.

In particular, the investigations revealed that TIM had engaged third parties to process personal data without conducting the necessary preliminary checks to ensure compliance with the safeguards required by the GDPR, and without adopting adequate organizational measures to constantly monitor compliance with data protection regulations by its sales network. 

The preliminary investigation made it possible to obtain documentary evidence (including screenshots extracted from the company’s systems) proving that commercial activation orders were entered into the company’s databases following unlawful telephone contacts. These abusive promotional calls originated from numbers not registered with the ROC and were directed, in many cases, at subscribers duly registered with the RPO. The unlawful conduct can be attributed to official TIM business partners, specifically the sales agencies XX, XX, XX, and XX.

The modus operandi adopted by these partners involved initiating sales processes through preliminary telephone contacts made without any consent whatsoever and using untraceable or altered (spoofed) phone numbers. Subsequently, in order to artificially mask the unlawful origin of the contact, the partners asked the data subjects to click on a specific link received via SMS or messaging services. This operation was designed to generate a fictitious, independent request for follow-up contact (lead), intended to “clean up” the data trail vis-à-vis the parent company. Consequently, the partners reported to TIM that they had acted in response to a spontaneous request from the User through regular channels, concealing the actual and abusive telemarketing activity carried out beforehand.

a) Review of Individual Investigation Files

In order to outline the objective scope of the violations identified, the findings regarding the individual files examined by this Authority are set forth below; these findings confirm the ineffectiveness of the Company’s compliance controls.

- File No. 425095: During the inspection, it emerged that certain orders in the name of the data subject, entered into the company’s systems by TIM’s partner XX, were listed as resulting from spontaneous online requests for follow-up contact regarding leads and subsequent regular phone calls. The investigation revealed a completely different reality: the contacts did not stem from the User’s initiative but represented the final stage of repeated and persistent abusive promotional calls originating from unregistered numbers (including WhatsApp accounts improperly bearing the Company’s logo). TIM’s preventive control and ex-post monitoring systems proved inadequate, as they recognized only the “cleaned-up” calls that occurred after the generation of the fictitious leads as valid, ignoring the entire preceding unlawful phase. The structural inadequacy of the controls is confirmed by the fact that, despite hundreds of thousands of contacts, the Company detected only minor discrepancies without ever reporting any major issues involving the agency in question.

- Cases Nos. 496215 and 437668: The complainant filed a complaint with the Public Prosecutor’s Office, alleging that he had received automated calls on behalf of TIM and that leads were generated via links sent through WhatsApp. Following the complaint, the Data Protection Authority sent a request for information to TIM. The case files confirmed that multiple unlawful contacts had been made to promote TIM services using spoofed phone numbers by agencies within the company’s sales network. Specifically, the violations were attributed to the actions of XX in connection with an activation order (file no. 496215) and to the actions of XX (file no. 437668). In this case as well, the company’s information systems architecture processed the contracts without detecting the illegality of the upstream data processing.

- File No. 434470: On February 18, 2025, the complainant, acting on behalf of third parties, reported automated calls to a subscriber registered with the RPO on behalf of TIM, originating from numbers not registered with the ROC. During the inspection, evidence was obtained regarding an activation order entered into TIM’s information systems by the business partner XX. The documentation on file unequivocally confirmed that the subscription to the service originated from abusive commercial contacts carried out using CLI spoofing techniques, thereby circumventing the Company’s Tracking and verification systems.

- Case No. 444902: The complainant reported, on behalf of a third party, an automated call received on January 23, 2025, on a number duly registered with the RPO to promote TIM services. Following an initial expression of interest, the data subject was contacted again by a self-proclaimed consultant via a WhatsApp profile bearing the TIM logo to provide contract details. To complete the subscription, the data subject was asked to click on a link received via SMS from another untraceable number. This link led to a web page where data was entered to artificially generate an independent request for a callback (Lead). The investigation revealed an activation order processed and entered by TIM’s official partner XX. In the system, the transaction appeared legitimate and resulted from a “Lead” associated with the data subject’s account. The actual facts, however, contradicted the findings of TIM’s management portal: the contact did not stem from a spontaneous request by the customer, but was the result of multiple unauthorized contacts that occurred on the same day and an SMS containing the link to generate the false request. A particularly serious issue emerged in the fact that Partner XX had already been subject to Level II audits by TIM in November 2023, which had concluded with a rating of “INADEQUATE.” Extremely serious violations had been identified, such as the processing of data by an unauthorized subcontractor and the use of real leads in a test environment. Nevertheless, TIM had limited itself to issuing a formal warning and implementing a paper-based monitoring system that proved to be completely ineffective.

- File No. 513320: In this case as well, the order was entered into TIM’s official systems by a TIM partner, XX., confirming the vulnerability of the Company’s acquisition channels to data flows of illicit origin. Upon discovering the unlawful processing of her data through unauthorized channels, the complainant subsequently requested that TIM cancel the order and the contract, as well as identify the partner responsible for the calls. Following the Data Protection Authority’s request for an investigation (October 3, 2025), TIM responded to the complainant on October 22, 2025, and to the Authority on October 23, 2025.

- File No. 518841: In a complaint filed on September 9, 2025, the complainant alleged that he had been deceived by an individual who falsely claimed to be an agent of the competitor “XX,” who fraudulently induced him to switch to TIM by providing false technical information. The case files provided further evidence that personal data unlawfully obtained from unidentified third parties acting on behalf of the Company had been entered into TIM’s information systems via activation orders. The complainant expressed concern that unidentified individuals had obtained all of his personal and sensitive data (including his address), creating a high risk of retaliation and further unlawful use of such data.

- Case No. 557370: The complainant reported receiving unsolicited promotional emails, noting that he had refused to give consent for marketing purposes from the time the contract was signed and on every subsequent occasion. The documentation included in the case file revealed that TIM had sent promotional communications to the data subject without prior and valid consent.

b) Analysis of Aggregated Data and Obvious Discrepancies

The structural inadequacy of the compliance and monitoring system established by TIM emerged unequivocally from the statistical analysis and the cross-referencing of log files with the monthly activation volumes provided by the Company itself, with particular reference to the month of November 2024.

Operational data relating to sales agencies reveal glaring inconsistencies that should have prompted the Company to immediately block the data flows and trigger security alerts:

Sales Partner Declared Leads Contacts Made Volume Discrepancy Conversion Rate / Outcome

XX 17,388 22,242 +4,854 contacts compared to leads Contract activation rate < 4%

XX 5,758 5,919 +161 contacts compared to leads 80% of Users unreachable; activation < 10% (509 orders)

XX 6,075 16,102 +10,027 contacts compared to leads Response rate of 1/3 (5,904); activation at 11% (708 orders)

 

From a logical and legal standpoint, the generation of a lead presupposes an independent, targeted, and informed request by the individual User. Therefore, the presence of such an excess of contact attempts (over 10,000 more than the requests in the case of XX), combined with extremely low conversion rates (less than 4% for XX) demonstrates in re ipsa the inauthenticity of the lists and the unlawfulness of the preliminary contacts.

Added to this is a complete lack of criteria for qualifying and selecting agencies. TIM failed to verify that the size of the partners’ workforce was commensurate with the volume of contacts generated (over 20,000 contacts per month per agency, equivalent to approximately 1,000 calls per day). This organizational shortcoming made it impossible to detect in advance the use of automated calling systems (bots) or the outsourcing of services to unauthorized call centers operating under unauthorized subcontracts.

Following the in-depth investigations conducted in connection with case files nos. 425095, 496215, 437668, 434470, 444902, 513320, 518841, and 557370, the Authority charged TIM with the following violations:

- Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having made, or allowed third parties to make, promotional contacts with Users listed in the Public Do Not Call Registry without a valid legal basis;

- Art 5, para 2, of the Regulation, for violating the principle of accountability by failing to adopt adequate control and oversight systems for the sales network;

- Articles 24, 25, and 28 of the Regulation, for failing to adopt appropriate technical and organizational measures to prevent the use of disguised phone numbers and to ensure compliance with the instructions provided to Partners;

- Art 32 of the Regulation, for the insufficiency and inadequacy of security measures relating to consent collection processes and order-processing systems. 

2.1.3. TIM’s Handling of Requests to Exercise Data Subject Rights

The findings of the preliminary investigation revealed systemic issues in the controller’s handling of requests to exercise rights (pursuant to Articles 15–22 of the Regulation), attributable to two broad areas of concern.

a) Obstacles to the exercise of data subject rights and inadequacy of opt-out procedures

A first group of cases concerned TIM’s failure to process requests by data subjects to exercise their data subject rights, as well as cumbersome and inadequate opt-out procedures.

Specifically:

- Case No. 478291: The data subject continued to receive communications for over four months after exercising the right to object, as the Company failed to update its systems (thereby keeping consent active) and to add the email address to the blacklist.

- Case No. 519239: The systematic sending of promotional communications without consent or a contractual relationship was contested, compounded by the failure to respond to certified emails (PEC) requesting erasure and by the malfunctioning of the opt-out link.

- Cases Nos. 438663 and 517806: The complainants reported that they continued to receive promotional communications despite explicit requests for revocation and erasure sent via certified email (PEC) to the address “TIMaltuofianco” or to the Data Protection Officer (DPO). Both also reported that the unsubscribe link was ineffective, as it was subject to complex technical requirements (a malfunctioning login or mandatory registration).

With regard to the aforementioned cases, TIM was charged with violations of Articles 17 and 21 of the Regulation (for failing to comply with the requests of the data subjects), and Articles 6(1), para 1, subparagraph (a) of the Regulation, and Article 130, paragraph 2, of the Code, for sending repeated promotional messages without a valid legal basis.

With regard to the excessive complexity of the procedure for unsubscribing from mailing lists—which the complainants (cases nos. 519239, 438663, 517806, 443623, 448740, and 557370—complained was “cumbersome” to the extent of creating undue obstacles for the data subject, TIM was charged with violations of Articles 12, para 2 (for failing to facilitate the exercise of rights), and Articles 15–22 (for violating applicable provisions regarding the exercise of rights, rendering requests for objection or erasure ineffective) and Article 24 (for failing to implement adequate technical and organizational measures to promptly and effectively accommodate the wishes of data subjects).

A review of the case files revealed that TIM did not ensure the criteria of simplicity and immediacy required by Article 7, para 3, of the Regulation. On the contrary, it made unsubscription contingent on complex steps, such as interacting with virtual assistants, downloading specific applications, or the requirement to log in to the company’s Restricted Area. This last requirement constituted a prohibitive obstacle, especially for “non-customers” who lacked login credentials.

b) Failure to Respond, Delayed Response, or Inadequate Response to Data Subjects’ Requests

A second group of cases revealed non-compliance with the obligation to provide a timely response to data subjects, in violation of the provisions of the Regulation, including Art 12(3).

With regard to cases nos. 425095, 513320, 500303, 520955, and 514826 concerning the failure to provide, delayed, or inadequate response to requests to exercise rights, it should be noted that Art. 12 of the Regulation requires the data controller to respond to the data subject without undue delay and, in any event, no later than one month after receipt of the request. This deadline may be extended by two months only if necessary, taking into account the complexity and number of requests.

A review of the documents revealed the following:

- File No. 425095: The Company responded to the complainant’s request (seeking to know the identity of the partner who placed the orders) only on March 26, 2025, that is, 120 days after the initial request dated November 26, 2024.

- File No. 513320: TIM responded to the complainant’s request only on October 23, 2025—51 days after the request dated September 2, 2025 (after citing, on October 2, the “particular complexity” of the transaction).

- Case No. 500303: TIM responded to the two requests for erasure submitted by the complainant only on May 14, 2025—that is, 85 days after the request (dated February 18, 2025).

- Case No. 520955: It was determined that the Data Controller completely failed to respond to a request pursuant to Articles 15–22 sent via certified email (PEC), after the 30-day deadline had expired without a response.

- Case No. 514826: In response to a request for access aimed at determining the origin of the data used for promotional calls, the Company provided the data subject with a response that was merely partial and significantly delayed (88 days after receipt).

The circumstances described above constitute an alleged violation of Article 5, para 1, subparagraph a) and para 2, as well as Articles 12, 15, 17, and 21 of the Regulation due to the delayed and inadequate response to requests for access, erasure, and objection.

3. THE COMPANY’S DEFENSES

3.1. TIM’s Proper Governance

In response to the Authority’s allegations, TIM filed its defense brief on March 26, 2026 (Ref. No. 47656 of March 27, 2026), noting the following.

First, TIM noted that, at the time of the inspection, the Company had adopted a governance model fully compliant with the requirements of the Code of Conduct for Telemarketing and Telesales Activities (finally approved by the Authority on March 7, 2024; hereinafter the “Code of Conduct”). Consequently, TIM had developed a legitimate expectation regarding the fairness of its conduct and the appropriateness of the investments it had made.

Specifically, the Company emphasized that Codes of Conduct are “precisely accountability measures aimed at ensuring that data controllers strike a proper balance of interests, thereby relieving them, at least in part, of the need to prove their own accountability and the compliance of the measures adopted” (EDPB Guidelines 1/2019 on codes of conduct and monitoring bodies under the Regulation).

According to TIM, the Authority could have raised objections only in the event of failure to implement the measures provided for in the Code of Conduct. Conversely, if technological developments had rendered those measures inadequate, it would have been the Authority’s responsibility (and not the Company’s) to intervene with general guidance or to request their update (pursuant to Article 40 of the Regulation).

Second, the Company noted that the calls in question were actually made from numbers outside the official TIM network and by third parties operating covertly. These entities acted in flagrant violation of company directives, using illegal practices such as CLI (Calling Line Identification) spoofing to conceal their identity.

TIM emphasized that combating this phenomenon cannot be effectively left to individual private operators alone, requiring systemic enforcement and regulatory measures (e.g., AGCom Resolutions No. 106/25/CONS and No. 271/25/CONS), which have so far proven only partially effective due to the adaptability of the illegal networks.

Third, following the findings of the inspection and as evidence of its due diligence, in order to further curb fraudulent conduct, TIM stated that it had enhanced its control system with extensive measures. Following the inspection, TIM strengthened its control system against fraudulent conduct on three distinct levels. On the contractual and legal front, it initiated disciplinary actions against non-compliant agencies, including the termination of contracts with 10 Consumer agencies. In terms of oversight, it established—under the coordination of the DPO—an extraordinary control system based on mystery shopping audits and the “Valutometro” scoring algorithm. Finally, on the technical and organizational level, the company has introduced real-time blocking of duplicate IP addresses, immediate SMS opt-out, the “STOP SPAM” feature on the MyTIM App, and the suspension of the “Refer a Friend” offer.

TIM argued that any penalty based on strict liability would be unlawful, citing Article 3 of Law 689/1980 and the case law of the CJEU (Cases C-683/21, C-768/21, C-807/21).

The Company noted that the case law of the Court of Justice is consistent in affirming that the Regulation excludes any instance of strict liability. The imposition of financial penalties requires specific proof that the conduct is attributable to the controller on the grounds of intent or negligence (Cases C-683/21, C-768/21, C-807/21).

According to the Company, it is undisputed that if the processor exceeds its instructions or acts for its own incompatible purposes, it assumes the status of an independent controller, thereby severing the link of liability to the controller.

The Company concluded by arguing that conduct beyond that already carried out cannot be held against it. The alleged violations stem from the independent and fraudulent actions of third parties who acted outside the scope of TIM’s control and instructions. Therefore, the Company urged the Authority to direct its inspection and enforcement activities directly toward the illegal agencies and call centers that constitute the “underground network,” since the client is free of any negligence or willful misconduct.

3.2. The Phenomenon of Leads

In its defense brief, the Company contested the Authority’s findings regarding the alleged inadequacy of the technical and organizational measures adopted, opposing any mandatory imposition of an opt-in model in place of the current opt-out system. 

Specifically, TIM argued that any injunctive or regulatory order would be premature, citing the need for prolonged monitoring of the effectiveness of the new opt-out system (which had been implemented only a few days earlier), given that, as of now, no complaints had been received from data subjects indicating that it was malfunctioning.

The Data Controller noted that neither the opt-in nor the opt-out would be effective tools for curbing the phenomenon of so-called “underground” telemarketing (illegal calls made by third parties outside the company’s scope). The Company further clarified that the risk of massive fraudulent entries of personal data is already adequately mitigated by the established procedures for IP address tracking.

According to the Company, any defect identified during the lead acquisition phase (such as a telephone contact initiated without an appropriate legal basis) would not affect the consent subsequently provided by the data subject, which would remain free and informed. In this regard, TIM emphasized that the finalization of contracts always requires an additional and specific expression of intent by the customer, distinct from and subsequent to the generation of the lead.

TIM pointed out that the opt-in standard is not an established practice in the current relevant market. In the Company’s view, the Authority’s mandatory imposition of this standard would result in an unjustified competitive disadvantage compared to other economic operators in the sector.

Finally, appealing to the principle of loyal cooperation, the Company expressed its hope for the initiation of an institutional dialogue with the Authority, aimed at jointly identifying alternative security measures and governance safeguards, should the current framework be definitively deemed unsuitable following the conclusion of the preliminary investigation.

3.3. Promotional Contacts Without Consent

The Company noted that it had acted correctly in all contested cases by managing leads that, to the best of its knowledge, were valid, and that it had no way of knowing about any unsolicited calls made prior to the lead.

It was also clarified that:

- the phone numbers used for the unsolicited calls did not belong to the TIM network;

- the activation orders generated were never converted into valid contracts;

- in any case, the Company terminated its contractual relationships with the agencies in question, specifically XX, XX., XX., and, subsequently, XX.

3.3.1. TIM’s “Activation Orders” System

As a preliminary matter, TIM explained the technical and operational functioning, within its corporate systems, of the activation orders that are the subject of the Authority’s objections.

The purchase of a TIM service requires the prior creation of a so-called “activation order,” a preliminary step preceding the actual conclusion of the contract. This order is managed through the “CCC” sales system, which sales representatives access using their individual credentials (username and password).

In cases of remote sales, once the sales representatives have completed the necessary personal verification (confirming the potential customer is of legal age) and technical verification (service coverage at the requested location, for example, for landline and internet service), the potential customer has the opportunity, before finalizing the activation order, to provide and manage their consents regarding personal data data protection, as well as to select the payment and subscription methods (choosing between Digital Confirmation or authentication via OTP).

With specific regard to privacy consents, the operator explains the privacy notices to the potential customer over the phone and records the preferences expressed during the call in the system. Consequently, before the order is formally issued, the computer system automatically sends a summary of the consents granted via email, which the data subject may freely and at any time modify.

Subsequently, the potential customer receives—again via email—an additional communication containing a summary of the commercial offer, the required contractual documentation, and the privacy notice regarding the processing of personal data. Only at this stage does the agent proceed to fill out the administrative section titled “Contact Type Tracking,” indicating the phone number used for contact and the source of the data (e.g., acquisition via leads, internal TIM lists, etc.).

After receiving the aforementioned documentation, the potential customer chooses the method for finalizing the contract (OTP or Digital Confirmation). In the first case, the order is validated and issued only once the agent has received the confirmation code from the customer. In the case of Digital Confirmation, the order is considered confirmed only when the company’s systems record the User’s direct input.

The Company reiterated that, for the purposes of concluding the contract, the proposal always originates from a customer request, and the contract is considered finalized only upon activation by TIM. It follows that receipt of the activation order identification code does not imply the automatic conclusion of the contract with TIM.

3.3.2. Analysis of Individual Investigation Files

With regard to the individual cases, TIM provided the following clarification.

- File No. 425095: TIM clarified that the calling numbers never belonged to the TIM network. Internal investigations revealed that three separate sales orders were generated in the complainant’s name following three contact requests submitted independently on the XX Digital Agency portal. Therefore, the Company found in its systems only a record of a validly created lead, the creation of which was not contested by either the data subject or the Authority. In any case, TIM terminated all contractual relationships with the aforementioned agency effective July 2025, and it has been confirmed that the three activation orders were never converted into valid contracts.

- File No. 496215: TIM highlighted the following: the disputed calls originated from numbers not assigned to the TIM network; the system showed a lead that had been correctly acquired through the aforementioned Agency XX (a partner with whom TIM has terminated its relationship); and the related activation order was never finalized into a contract. Regarding consent, the Company promptly sent the petitioner—at the same time the order was issued—a summary email so that the petitioner could review it and, if necessary, correct the preferences provided over the phone (it was noted, however, that only the consent for marketing purposes related to TIM products and services was marked as “YES,” while all other purposes were marked as “NO”). TIM therefore processed a lead that, to the best of its knowledge, had been acquired in full compliance with regulations.

- Case No. 437668: TIM noted, as a preliminary matter, that the defense brief constitutes the first defense submitted in the aforementioned case. The Company noted that the calling number does not belong to TIM. The documentation on file clearly showed that the complainant deliberately prolonged the conversation with the alleged operator in order to conduct an independent investigation, and not to activate a service. In fact, the contract was never concluded. The Company’s IT systems simply received a formally valid lead transmitted by XX; the Company had no way of foreseeing the existence of deceptive or disruptive conduct occurring upstream in the supply chain.

- File No. 434470: TIM noted that it became aware of the report exclusively during the Authority’s inspection operations, as the report was submitted by the complainant on behalf of third parties. The Company was able to identify the data subjects solely thanks to the activation order codes provided by the complainant. TIM stated that its systems showed the presence of a formally correct lead, provided by Digital Agency XX (with which TIM has terminated its contractual relationship). The applicant, having nevertheless continued the telephone conversation, initiated an activation order on February 6, 2025, which never resulted in the conclusion of a contract.

- File No. 444902: The Company’s representative stated that the data subject complied with the follow-up procedure until she received an SMS link traceable to Digital Agency XX. The complainant then proceeded to enter the data for the sole purpose of revealing the identity of TIM’s business partner. In this case as well, TIM objected that no contract had been concluded, and following the aforementioned investigations, TIM immediately terminated its partnership agreement with XX.

- File No. 513320: TIM determined that the reported phone numbers were not in use by TIM or its sales network, nor were they registered with the R.O.C. The system recorded only one lead generated by Agency XX, which entered the activation order, which was subsequently canceled at the explicit request of the data subject. To ensure maximum protection for the user, TIM nevertheless recorded the marketing opt-out for the reported mobile line in its databases, even though the line was not registered on the TIM network.

- Case No. 518841: As a preliminary matter, TIM noted that the defense brief constitutes the first defense filed in this case. TIM confirmed receipt of a lead that was properly uploaded by Agency XX. Following contact, the data subject initially confirmed their intention to proceed (a circumstance documented in the complaint itself), but then exercised their right of withdrawal on September 14, 2025, requesting cancellation of the order—a request that was promptly honored and carried out by the Company. In response to the Authority’s finding regarding the use of unlawfully obtained data, it was argued that TIM could not have been aware that the contract was preceded by a call made without first obtaining consent. The Company noted that it had acted in strict compliance with Article 16 of the Code of Conduct, promptly accommodating the customer’s subsequent change of mind. 

- Case No. 557370: As a preliminary matter, TIM pointed out that, in this case as well, the defense brief constitutes the first defense filed in the case at hand and that it is not related to the creation of a lead. The Company noted that the User never received any marketing communications. The emails in question concerned exclusively contractual updates, specifically the right to a specific contractual benefit (the legal basis would be Article 6, paragraph 1, subparagraph b) of the Regulation), which provided for the TIM Vision service to be offered as a free gift during the Christmas season. Therefore, TIM did not send any promotional communications without consent, and no charges can be brought against TIM in relation to this specific case. Finally, regarding the opt-out procedure, it was found that even if the petitioner had formally exercised that right, he would still have received the aforementioned service communications, given their strictly contractual and non-commercial nature (since marketing consent had already been denied in advance and recorded in the system).

3.3.3. Additional Measures Being Considered by TIM

To supplement the actions already underway, TIM has stated that it intends to tighten the selection process for digital agencies through a system based on specific checklists. The goal is to verify the organizational adequacy of partners in advance by requesting details on the number of resources employed, operational capacity, prior experience, and the degree of compliance with privacy regulations, thereby screening out undersized or inadequate entities.

The Company also intends to enhance its monitoring systems by establishing new “alert triggers” to initiate more in-depth checks (Level II audits). These alerts will be triggered both through the strategic use of post-activation surveys and through the identification of statistical anomalies, such as productivity that is disproportionate to the declared workforce or anomalous contact rates.

Finally, as an additional safeguard, TIM is considering extending the trial period for new partners. This measure would allow the company to have a longer period of time to promptly identify and address any issues or irregularities from the earliest stages of the partnership.

3.4. Handling Requests to Exercise Rights

TIM first noted that the handling of requests to exercise rights also falls within the scope of activities governed by the Code of Conduct. In particular, TIM’s handling of requests to exercise rights is governed by internal procedures that precisely define (i) the designated channels for receiving requests; (ii) the requirements for identifying the requester; (iii) the workflows to the relevant departments; (iv) response times; and (v) the procedures for tracking requests and updating blacklists.

3.4.1. TIM’s Timely Action in Response to Customers’ Requests to Stop Receiving Promotional Communications

Regarding the complaint concerning the failure to promptly comply with customers’ requests to revoke consent to promotional communications, the Company noted that its email promotional campaigns are directed exclusively at customers who have provided specific consent for marketing purposes and not at subscribers to newsletter services. TIM also had a representative who stated that it is in full compliance with Article 12, para 6 of the Regulation regarding the digital authentication measures required for access to the MyTIM Area, characterizing them as security measures necessary to verify the identity of the requester and to prevent the risk that third parties might interfere with the data subject’s profile by altering their intent.

Furthermore, data subjects have various channels available to exercise their rights and revoke their consent, such as writing to TIM’s institutional certified email (PEC), contacting the DPO, or calling customer service, etc.

With regard to the specific individual cases, TIM noted the following.

- File No. 478291: The Company argued that its conduct was fair, having responded to the data subject’s request within the thirty-day deadline, confirming that the request had been received. TIM emphasized that the subsequent receipt of promotional communications was due exclusively to the technical time required for “specific system updates,” during which the Company nevertheless kept the User informed until the final opt-out. TIM contested the complainant’s assertion regarding the absence of prior contractual relationships, noting that the email address on file was duly registered as the contact information for a Business account with marketing consent that had been actively confirmed from the outset. The Company also noted that the failure of the opt-out procedure was due to repeated errors by the complainant, who entered his personal tax ID number instead of the one associated with the customer profile, causing the control systems to automatically reject the request.

- File No. 438663: The Company pointed out the complainant’s error in identifying the communication channel, as the complainant had submitted the request to a TIMaltuofianco corporate certified email (PEC) address specifically and exclusively designated to receive reports regarding the phenomenon of so-called “unsolicited telemarketing” carried out by third-party operators. The complainant’s error prevented the automatic processing of the revocation, which TIM fully complied with as soon as the circumstances were clarified following the transmission of the documents by this Authority.

- File No. 517806: The Company pointed out that the initial request was sent to a Data Protection Officer’s (DPO) email address that had already been formally decommissioned, preventing its proper registration. TIM clarified that a subsequent request sent to the institutional certified email address was not processed due to an unforeseen “technical anomaly” in the IT systems; however, the Company proceeded to definitively adjust the consents in accordance with the data subject’s wishes.

- Cases Nos. 443623 and 448740: TIM argued that the complainants never submitted formal requests to exercise their rights to the Company, having instead contacted the Data Protection Authority directly. The Company also refuted the alleged absence of a contractual relationship with one of the data subjects (Case No. 448740), confirming that she held multiple active lines. Finally, TIM noted that the complainants had in any case unsubscribed on their own through the company’s web portal.

- File No. 557370: The Company ruled out the commercial nature of the disputed emails, classifying them as communications regarding contract updates and the provision of free holiday benefits. TIM further clarified that the customer’s status had already been set to “marketing consent denied,” rendering the initiation of a revocation procedure materially unnecessary, and that the Company had in any case provided formal confirmation to the data subject.

3.4.2. Cases Characterized by Particular Complexity

TIM strongly contested the Authority’s assertion that the use of the extension of time limits provided for in Art 12, para 3, of the Regulation constitutes the Company’s standard operating procedure. The consolidated data for the year 2025 in the Consumer segment demonstrated the absolute effectiveness and resilience of the Company’s organizational processes: out of a total of 54,376 requests processed, 98.30% (equal to 53,449 requests) were resolved within the standard 30-day deadline. Cases where this deadline was exceeded represented a completely residual and statistical percentage (1.24% between 30 and 90 days and 0.47% beyond 90 days), attributable solely to particularly complex investigations (such as multi-system reconstructions, document verifications with third parties, and checks on external numbering systems). The Company also pointed out that identifying business partners and reviewing individual case files required extensive cross-checking across multiple application environments and complex external interactions, ruling out the notion of a “simple query” as hypothesized by the Authority.

With regard to the specific cases, TIM noted the following.

- File No. 425095: The access request (November 2024) required complex verification activities involving third parties and phone numbers not in use by the Company. TIM provided an interim response within thirty days, requesting identifying documentation in accordance with Art 12, para 6, of the Regulation. Once the investigation was completed, the Company sent its final response on February 24, 2025, confirming that the contacts in question were unrelated to its organization.

- File No. 513320: The request, aimed at identifying the source of an allegedly irregular sales contact, received an initial interim response within 30 days and a final response in October 2025. The investigation revealed that the order was placed and then canceled by a partner in the sales network. TIM not only promptly notified the data subject and the Authority but also took appropriate protective measures by adding the line to the exclusion lists and formally filing a complaint against the responsible partner.

- Case No. 500303: The matter did not involve the exercise of a right related to personal data protection, but rather the fulfillment of a contractual right (i.e., a request for erasure of an email account). Due to a technical issue related to a landline recently canceled by the User, which hindered the automatic deactivation of the email account, the Company took action through manual intervention by its technical staff. The matter was resolved to the data subject’s full satisfaction, and TIM provided timely formal and telephone responses throughout the year 2025. 

- File No. 520955: In this case as well, the original request dated July 2025 concerned solely a contractual right related to the renewal of login credentials, to which the Company provided a correct and timely response. The subsequent privacy request regarding data storage periods (August 2025) was not processed due to an isolated clerical error in the IT classification system, which caused the internal workflow to close automatically; this constituted an exceptional anomaly and is not representative of standard company practice.

- File No. 514826: In response to the access request filed on July 17, 2025, regarding alleged promotional contacts and a request for information on the disclosure of data to third parties, TIM provided an initial interim response within the statutory timeframe and subsequently issued its final response on October 15, 2025. Internal investigations ruled out any violation or accountability on the part of the Company, as the calling numbers could not be traced back to TIM or to its network of authorized partners.

3.5. Measures Adopted by TIM

Regarding the procedures for handling requests to exercise data subject rights, the Company highlighted the implementation of numerous organizational and procedural safeguards aimed at continuously strengthening its privacy governance. Among the measures already in place, TIM listed the adoption of automated classification systems for requests received via PEO and PEC channels, based on text recognition rules, the activation of automated supplementary notifications in the event of technical anomalies in attached files, as well as the extension of the timeline monitoring system (SLA Management) to nearly all requests to ensure end-to-end process control.

From a strictly operational and human resources management perspective, the Company acknowledged a significant strengthening of its internal organizational structure through the establishment of specific, distinct teams tasked, respectively, with reviewing traffic logs, handling privacy requests other than those related to traffic logs, and addressing reports submitted to the Data Protection Officer (DPO). The Company reported that it supplements these coordination mechanisms with regular, specialized training sessions for staff, supplemented by surveys and the sending of systematic reminders focused on the need to comply with the time limits for processing cases.

Finally, with regard to medium-term strategic planning, TIM’s representative stated that further corrective measures aimed at improving the timeliness and quality of the Company’s operations are currently under advanced evaluation. Specifically, the Company has formalized its commitment to optimizing messages that redirect users to dedicated thematic channels, extending automatic classification to additional corporate email inboxes, and, lastly, drastically simplifying the procedure for withdrawing consent for direct marketing purposes, to be achieved through the complete elimination of the previous IT authentication mechanisms.

3.6. Failure to Comply with Procedural Deadlines and Violation of the Ne Bis in Idem Principle

TIM argued that the Authority’s power to impose sanctions had lapsed due to the expiration of the 120-day deadline for serving the notice of charges, pursuant to Table B of Regulation 2/2019. According to the Company, this limitation period began on April 17, 2025, the date on which the collection of investigative evidence was completed following the conclusion of the inspection activities (formalized through the notice of resolution of the Reservations). Therefore, taking into account the summer suspension of deadlines (August 1–31) provided for in Art. 6, paragraph 1, of the aforementioned Regulation, the deadline for the valid service of the notice of charges would have inevitably expired on September 15, 2025.

For the purposes of calculating procedural deadlines, TIM also noted the clear inadequacy of the voluntary communications sent by the Company to produce any suspensive effect. According to TIM, the suspension mechanism provided for in Art. 7 of Regulation 2/2019 applies exclusively to the period of time between a formal request for information from the Authority and the party’s response thereto. It follows that the unsolicited submissions presented by TIM would not have interrupted or suspended the course of the proceedings. The Company also considers the subsequent requests for information made by the Authority in October 2025 to be irrelevant, as they occurred at a stage when the Authority’s power to impose sanctions had already expired.

In the Company’s view, even if one were to hypothetically grant suspensive effect to the aforementioned unsolicited submissions, the deadline would in any case have expired on January 20, 2026.

Finally, the Company considered the Authority’s practice of consolidating complaints during the proceedings to be unlawful: according to TIM, the regulations invoked for this purpose would have justified joint consideration only for the purpose of issuing general measures, thereby revealing their incompatibility with the adoption of specific sanctioning acts. In light of the foregoing, TIM requested the immediate dismissal of the proceedings.

In addition to the Authority’s loss of sanctioning authority, in its defense briefs, The Company also represented that the issues concerning the governance of telesales and telemarketing channels, as well as the system for monitoring the data chain from initial contact to contract completion, are currently sub judice. TIM has pointed out that these issues are, in fact, the subject of a court-appointed expert report (CTU) ordered by the judicial authority in the context of the proceedings (R.G. 23522/2023) initiated by the Company itself to challenge the previous Sanction Order No. 183/2023 issued by this Authority.

Regarding the court-appointed technical expert report, the Company emphasized that the questions posed by the judge largely mirror today’s allegations. Specifically, TIM noted that the court-appointed expert was tasked with assessing the adequacy of the Company’s past and current systems designed to ensure the traceability of transactions, the lawfulness of promotional contacts made using numbers registered with the ROC, and the proper handling of requests from data subjects. According to TIM, the expert investigation is specifically aimed at identifying any additional corrective measures the Company should have adopted to comply with current regulations.

Based on these preliminary findings, the Company argued that the imposition of an additional and independent sanction by this Authority would be irreconcilably at odds with the rules on lis pendens (resulting in the erasure of the lawsuit from the docket pursuant to Article 39 of the Code of Civil Procedure) or the rules on res judicata on the merits (pursuant to Article 2909 of the Civil Code). Citing Supreme Court case law, TIM argued that res judicata covers both the claims asserted and those that could have been asserted, precluding the repeated exercise of sanctioning power over the same subject matter of the dispute, in order to prevent the endless proliferation of lawsuits and the risk of conflicting rulings.

Finally, the defense argued that the two proceedings are substantively and legally identical, as they share the same triad of constituent elements. In particular, the Company asserted that the parties (the Authority and TIM), the substantive claim (the annulment of the order and the consequent validation of corporate governance), and the cause of action (the alleged inadequacy of corporate control systems over the data chain), and therefore contended that the Authority’s sanctioning action was precluded.

3.7. The Company’s Hearing

During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on May 6, 2026 (minutes ref. no. 69385), the Company reiterated its arguments in full, focusing on the ongoing strengthening of its accountability system. TIM emphasized that the problematic phenomenon of so-called “unregulated telemarketing” is attributable exclusively to fraudulent conduct carried out by abusive third parties operating outside the Company’s organizational framework with specific intent. Citing the guidelines of the Court of Justice of the European Union, TIM invoked the principle of specific subjective accountability on the part of the direct offenders, characterizing the Company as the aggrieved party burdened by onerous compliance costs and serious reputational damage.

With regard to the substantive findings, TIM denied that the personal data was originally unlawful, arguing that the “Lead” technique is systematically supported by the express consent of the data subject and noting that none of the thirty-six cases examined resulted in the formal establishment of a contractual relationship. The Company further argued that there are objective technical and regulatory limitations in combating the phenomenon of spoofing, specifying that the adoption of unilateral preventive blocking measures would pose a high risk of disruption to essential services; to this end, it emphasized the need for a systemic, erga omnes intervention under the direct supervision of the competent authorities.

With regard to technical and organizational risk mitigation measures, the Company outlined the substantial financial investments made to implement real-time IP address tracking and to strengthen opt-out mechanisms. Regarding oversight of the sales network, the Company noted that it had undertaken rigorous corrective actions during the first quarter of 2026, culminating in the termination of contractual relationships with non-compliant agencies, the introduction of binding onboarding procedures with preliminary “privacy maturity” assessments, and the establishment of contractual trial periods with the right to terminate at will. Finally, the Company acknowledged that it has provided extensive training to customer care staff and is set to roll out technological solutions aimed at simplifying the process of withdrawing marketing consent. 

Based on these factors, the Company requested that the sanction proceedings be dismissed.

The Authority took note of the comprehensive defense represented and set a deadline for TIM to file a detailed summary of supporting documents and an analytical breakdown of the financial investments made in the areas of technological and legal compliance.

In a letter dated May 15, 2026, ref. no. 75146/26, TIM provided evidence of the substantial costs incurred and/or to be incurred for the implementation of the measures outlined by TIM during the hearing and for additional activities to combat unsolicited telemarketing.

4. THE AUTHORITY’S ASSESSMENTS

Having examined the case file, the findings of the preliminary investigation, and the defense brief filed, the Authority considers the complaints raised by TIM to be unfounded and, accordingly, confirms (with the exception of certain minor violations) the Data Controller’s accountability with respect to the charges brought, for the factual and legal reasons set forth below, which are to be considered in conjunction with the observations and findings already expressed in the aforementioned statement of charges.

4.1. On TIM’s Governance

With regard to TIM’s defense arguments concerning the fairness of its governance and the “lack of culpability” regarding any conduct on the part of the Company, the following observations are made.

First, TIM commits a logical and legal fallacy by assuming that the formal adoption of a governance model automatically precludes fault.

Compliance with the provisions of the Code is not, in and of itself, sufficient if the measures implemented prove ineffective in practice, or if the processing continues to violate the provisions of the Regulation. It is not enough to demonstrate that formal rules have been “prescribed” for entities in the supply chain; rather, it is necessary to prove that their actual application and substantive effectiveness have been verified.

TIM emphasizes its adherence to the Code of Conduct, noting that “while the Code of Conduct does not exhaust accountability, data controllers adhere to the Code of Conduct with an expectation of legal certainty and the appropriateness of the prescribed measures.”

Specifically, the Company noted that Codes of Conduct are “precisely accountability measures aimed at ensuring that data controllers strike a proper balance of interests, thereby relieving them, at least in part, of the need to prove their own accountability and the compliance of the measures adopted” (EDPB Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under the Regulation).

The Company makes the mistake of equating adherence to the Code with a “free pass” that would guarantee it immunity from sanctions. Such an automatic assumption runs counter to both the core principles of the Regulation and the very wording of EDPB Guidelines 1/2019, which TIM itself cites.

EDPB Guidelines 1/2019 expressly clarify that “Adherence to a code does not in itself guarantee compliance with the Regulation nor immunity for the controller or processor from sanctions or accountability under the Regulation.”

Adherence may certainly be taken into account by the Authority in determining the severity of the sanction (as a mitigating factor, pursuant to Art. 83(2)(j) of the Regulation), but it does not eliminate the violation committed nor preclude corrective action. As clarified in the Guidelines: “in the event of a violation of any provision of the Regulation, adherence to an approved code of conduct may indicate a greater or lesser need to impose an effective, proportionate, and dissuasive administrative fine or to resort to another corrective measure by the supervisory authority.”

Second, TIM’s argument that, pursuant to Article 28(10) of the Regulation and the case law of the CJEU, accountability for unlawful processing would rest exclusively with the so-called “underground” entities —a phenomenon that is said to escape the controller’s control—cannot be accepted.

The Authority has outlined principles that impose specific obligations on the controller to supervise and monitor the activities of processors. Failure to implement such safeguards constitutes, for all intents and purposes, negligence on the part of the data controller (see, inter alia, Decision No. 352 of May 14, 2026 (web doc. No. 10262507); Decision No. 228 of April 10, 2025 (web doc. No. 10127930); Decision No. 205 of April 11, 2024 (web doc. No. 10008076)). Specifically, the Authority clarified that a controller may be considered “at fault” for a violation committed by the processor if the controller has failed to exercise due oversight or has not adopted the necessary supervisory measures to prevent unlawful processing. In essence: if the data controller fails to actively supervise, this “failure to supervise” constitutes the fault justifying the sanction. Similarly, the controller’s accountability for processing carried out by its employees or agents (including call centers) may arise when there is an organizational deficiency or a lack of supervision. Although the client is not absolutely liable for the unlawful acts of others, it is liable for its own “negligence in supervision” or “negligence in selection.”

It is undisputed that:

- unidentified third parties made unlawful calls (using numbers not registered with the ROC and directed at numbers registered with the RPO) in the interest of and on behalf of the Company, and the streams of unlawfully acquired contacts by these “unauthorized” parties were fed into the company’s systems via activation orders for the benefit of TIM itself;

- the selection of processors took place in the absence of qualification and selection criteria for the agencies. Suffice it to note, by way of example, that TIM failed to verify whether the size of the partners’ workforce was commensurate with the volume of contacts generated;

- The monitoring system relies on information entered directly by the data processors themselves into the company’s systems;

- The system failed to detect glaring inconsistencies.

It should be added that the phenomenon of “underground” practices in telemarketing is not an unforeseeable event or a force majeure; it is a systemic and structural risk of the sector, widely known. The principal (TIM), which outsources promotional campaigns, has a duty to secure the supply chain by prohibiting unauthorized subcontracting (Art. 28, para. 2) and, above all, to establish traceability systems capable of detecting such anomalies.

TIM cannot simply invoke the “adaptive spirit” of the “underworld” to claim victimhood. The fact that the company secures contracts and derives direct economic benefit from marketing campaigns without being able to guarantee the lawfulness of the supply chain that generated those leads makes it liable for its own failure to exercise due diligence.

Indeed, it is precisely the systemic and adaptive nature of the phenomenon—that is, its ability to change form to evade the controls put in place over time—that imposes on the data controller—who directly benefits from the proceeds of such promotional activities—a duty of supervision that is not static but proportionate to the evolution of the risk. This obligation must extend—including through appropriate on-site inspections—to the systematic analysis of inconsistencies discernible from the aggregated data as a whole, including, for example, the conversion rate of leads into actually concluded contracts and the incidence of customer complaints attributable to a specific agency. Only monitoring structured in this way—and not an isolated check of a single parameter—is capable of promptly detecting anomalies, as demonstrated, in the present case, by the discrepancies already highlighted in the narrative between reported leads and actual contacts made.

The Company also argues that it has “no visibility or control” over the phase “prior to the upload of the lead” and that it cannot “become aware of cases …in which the entry of data on the web form is prompted by prior unauthorized phone calls,” except through “complaints and reports received from data subjects and the authority.”

This argument cannot be accepted.

The Code of Conduct itself—which TIM states it has adopted as a model—does not permit any form of voluntary “blindness.” On the contrary, the Code imposes rigorous standards, requiring the client to verify the lawfulness of all steps leading to the generation of the contact, without limiting itself to the final stage of the process. It is expressly stated that: “Those adhering to this Code of Conduct ensure that the entire supply chain processes data exclusively on the basis of appropriate consent... [...].” “The controller guarantees, including through the necessary cooperation of its processors, full, timely, and constant oversight of the entire supply chain of entities involved in any preparatory or execution phase of the promotional campaign.”

With specific reference to the oversight of suppliers, it is stipulated that “Each adherent shall verify compliance with the requirements declared by the service provider through document review and/or internal inspection, at an appropriate frequency and using methods and tools suited to the actual situation...”.

Therefore, the fact that the leads arrived “clean” via a final web form does not justify the lack of oversight over the predatory techniques employed by the Company’s business partners (or downstream subcontractors) to drive Users toward those forms.

The controller, as the client benefiting from the generation of those commercial leads, has a duty of proactive oversight.

Placing “trust” in the Code of Conduct without actually applying its basic principle—namely, “full control of the supply chain and the preparatory phase”—amounts to evading accountability obligations. 

Therefore, the sanctions imposed by the Authority are not only legitimate but also fully in line with applicable European (EDPB) and sector-specific legal principles.

4.2. On the inadequacy of the technical and organizational measures adopted by the Company in managing its customer records (so-called “Leads”)

The objection alleging that the corrective measure was “premature”—based on the recent implementation of the opt-out mechanism and the alleged absence of direct complaints—is without merit. Through the concept of Data Protection by Design, European legislation imposes on the controller an obligation of proactive—rather than merely reactive—prevention. The temporary absence of formal complaints during the first thirty days of the measure’s trial period does not remedy a system architecture that is, from the outset, manifestly unsuitable for ensuring the accuracy of the data and the data subject’s actual intent. Compliance with the Regulation is assessed based on the intrinsic adequacy of the measure and not on the mere absence of complaints from users.

With regard to the “opt-out” system introduced by the Company during the investigation, it should be noted that sending an SMS requiring the user to “reconsider” or revoke consent—within a strict 5-minute deadline, no less—to auser added to the system by unidentified third parties reverses the legal model of consent, which requires (Art 4(11) of the Regulation and Recital 32) an unequivocal affirmative act by the data subject, and not merely their inaction within a predefined time limit. The data subject’s silence, far from being equated with consent, is identified here as the very prerequisite for the lawfulness of the processing, in direct contrast to what is expressly excluded by Recital 32 of the Regulation, according to which “silence, inactivity, or the preselection of checkboxes should not constitute consent.” The data subject, completely unaware that their data has been provided via the Lead form, is in fact forced to take action to prevent processing that they neither requested nor authorized, rather than the processing itself requiring, as a precautionary measure, an expression of their will. Furthermore, the chosen technical solution—namely, opening a link received via SMS—is itself at odds with the most basic precautions regarding cybersecurity and phishing prevention, and is therefore doubly unsuitable: in terms of the lawfulness and transparency of the processing, and in terms of the security of the means used to exercise the data subject rights.

TIM’s argument regarding the tracking of IP addresses as a measure allegedly suitable for mitigating the risk of fraudulent submissions is also irrelevant. The IP address log merely certifies the point of origin of the electronic connection but offers no evidentiary guarantee regarding the identity between the person filling out the form and the actual holder of the provided phone number. Regarding the inability of these measures to curb the so-called “underworld” of illegal telemarketing, it is reiterated that the continued existence of widespread illegal activity cannot in any way exempt the data controller from adopting adequate security measures within the scope of its responsibility.

Furthermore, the argument that full and informed consent, obtained at the time the contract is finalized, would have a remedial effect with respect to any defect in the original acquisition of the lead cannot be accepted. The processing of personal data begins at the very moment of its collection; both the collection and the initial follow-up contact for a commercial purpose (so-called “outbound calls”) are, therefore, “operations” or “set of operations” that constitute “processing” and that, by their very nature, require—in relation to the specific purpose (in this case, commercial promotion)—a valid, sound, and verifiable legal basis. An unsolicited telephone call made as a result of a “fake” or unverified lead already constitutes, in and of itself, a relevant processing of personal data pursuant to Article 130 of the Code and, as such, must be based on an adequate legal basis. Therefore, such processing cannot be subject to any retroactive regularization or validation.

To hold otherwise would lead to a result that distorts and runs counter to the rationale of the Regulation: admitting that subsequent consent, however genuine, could “clean up” an originally unlawful processing would amount to indirectly legitimizing the entire predatory technique of the fictitious lead, provided that the commercial operator ultimately succeeds in getting the data subject to sign up. In other words, the unlawfulness of the initial data collection occurs instantly and definitively at the time of processing, regardless of the outcome subsequently achieved; it is not subject to the parties’ control nor susceptible to retroactive regularization due to subsequent events, under penalty of substantially undermining the principle of lawfulness set forth in Art 6 of the Regulation and transforming it into a requirement that can be waived retroactively by the data controller who benefits from the violation.

Moreover, the very Code of Conduct invoked by TIM—which is intended to discourage clients from accepting contracts resulting from unlawful telemarketing activities—expressly provides that “if, following inspections, contracts are found to have been entered into as a result of an invalid initial contact, such contracts may continue to be performed provided that the client informs the data subject of the invalid origin of the contract and that the data subject confirms their intention to maintain it - the validity of contracts, with the possibility of canceling contracts concluded by telephone in the event of an unlawful initial contact” (see Art. 16, paragraph 6, of the Code of Conduct).

The argument based on the absence of an opt-in system in current “market practices” and the resulting risk of a competitive disadvantage is also without merit. The accountability requirement (Art 5, para 2, of the Regulation) requires the data controller to comply with the law regardless of the commercial practices adopted by competitors, especially where such practices result in a restriction of the rights of data subjects. There can be no exemption based on widespread violations of the law by third parties. On the contrary, it is precisely the accountability referred to in para 2 of Article 5 of the Regulation (which entails the general accountability of the controller under Article 24 of the Regulation and the aforementioned principles set forth in Article 25) requires that the principles governing the proper processing of personal data set forth in para 1 of the same article be applied, taking into account the context, nature, and potential risks of the specific processing carried out. Whether a particular measure is mandatory or not therefore depends not on market practices but on an examination of the specific processing in question.

Moreover, this Authority has already ruled against opt-out mechanisms structurally similar to the one adopted by TIM. In Decision No. 574 of May 9, 2024 (web doc. No. 10107938), the Authority criticized an SMS opt-out system with a time window of only a few minutes, deeming it unsuitable for discouraging the mass addition of phone numbers via bots and for protecting data subjects unaware that they had been subscribed, while reaffirming the preference for the double opt-in model. Similarly, in Decision No. 401 of June 20, 2024 (web doc. No. 10040382), the Authority ruled that a promotional communications system based on opt-out rather than opt-in was unlawful, and in Decision No. 330 of June 4, 2025 (web doc. No. 10143278), it censured the adoption, by third-party providers tasked with lead generation, of consent tracking systems lacking the necessary guarantees of verifiability. These precedents confirm that the Authority’s position on this matter does not constitute an ad hoc imposition in the present case, but rather the application of a well-established and publicly disclosed principle, of which the Company, as an industry operator subject to specific oversight, could not have been unaware.

With regard to the invoked principle of good faith cooperation, while acknowledging the Company’s stated efforts to comply, the Authority cannot refrain from imposing mandatory measures where the proposed measures are structurally deficient.

In light of the above considerations, it is reiterated that the adoption of a rigorous opt-in-based prior verification procedure (such as, for example, sending a One-Time Password —OTP—to validate the number) represents, as the technology currently stands, one of the technical and organizational measures that have proven to be effective and suitable for preventing the use of fictitious personal data and ensuring that the processing fully complies with the principles set forth in Article 25 of the Regulation.
Only by making the inclusion of phone numbers in contact databases contingent upon a positive, unequivocal, and pre-verified action by the actual owner of the telephone line can the necessary balance be achieved between the Company’s legitimate commercial expectations and the protection of the fundamental rights and freedoms of the data subjects.

4.3. On the systemic nature of the violations and the invalidity of consent (so-called “fictitious leads”). Groundlessness of the defense arguments regarding individual investigative files.

An examination of TIM’s defense brief and the investigative documentation reveals a pattern of widespread and systematic data breaches, attributable to a structural inadequacy in the Company’s organizational structure and the control mechanisms it has implemented to oversee the operations of its sales network (agencies and business partners). 

The defense’s argument—that the Company acted correctly by merely managing leads (requests for follow-up contact) that, within the system, appeared formally valid, since the data subject could not have been aware of the prior unlawful “harassing” calls—cannot be accepted.

As already noted, in fact, this argument stands in clear contrast to the core principles of the Regulation, and in particular to the frequently cited principle of accountability (Art. 5, para. 2, and Art. 24). The controller cannot, under any circumstances, hide behind the apparent formal correctness of the data entered into the system when the entire data collection architecture proves incapable of detecting and blocking anomalous data flows.

As amply demonstrated during the inspection, the leads in question cannot under any circumstances be considered validly provided. In fact, it has been proven that the “click” made by the user on the link received via SMS or messaging was in no way the result of an independent, spontaneous, and informed request by a data subject interested in TIM’s services. On the contrary, this action was artificially induced by the telecommunications operator during an initial abusive contact, carried out without consent, often through spoofing techniques or targeting subscribers registered with the RPO.

It follows that the initial contact is fundamentally unlawful under Articles 6 and 7 of the Regulation and Article 130 of the Code, irreparably invalidating the entire processing chain. The alleged “consent” obtained following deceptive and disruptive conduct—and, in any case, after processing had already begun—is neither free nor specific, but constitutes a mere technical expedient devised to fictitiously “clean up” the unlawful origin of the data in the controller’s databases. TIM, as the data controller, is liable for the conduct of the parties it engages (Art. 28 of the Regulation), as it is subject to serious negligence in both the selection and supervision of such parties.

Equally irrelevant is the fact that none of the cases in question resulted in the formal establishment of a contractual relationship with the Company, given that (i) this outcome did not stem from a direct initiative or careful monitoring attributable to the Company, but rather from the User’s own decision, who—after conducting an independent verification and realizing the fraudulent conduct—refused to confirm or requested the cancellation of the order; (ii) the mere activation order constitutes, in and of itself, sufficient evidence to prove the unlawful acquisition of Users’ personal data, carried out on behalf of TIM and fed into the company’s IT systems.

The inadequacy of TIM’s control systems is confirmed by an examination of the individual complaints and reports, with respect to which the Company’s justifications must be rejected for the following reasons.

- Cases Nos. 425095, 496215, and 437668: The Company argues that the calling numbers are unrelated to its own network; that the leads generated by XX and XX appear to be legitimate; and that no contract was concluded. This defense is without merit. The very fact that the Company’s systems accepted as “formally correct” leads resulting from persistent abusive calls demonstrates a violation of Art. 25 of the Regulation (Data Protection by Design and by Default). TIM’s IT systems were designed without taking into account the upstream phase of data processing, thereby allowing partners to enter flawed data. The subsequent termination of relations with the agencies constitutes an acceptable but belated remedy, which does not remedy the original unlawful data processing nor the failure to exercise preventive oversight.

- Cases Nos. 434470 and 444902: In these instances as well, the Company argues that the leads generated by XX and XX appear to be legitimate. In this regard, reference is made to the arguments already presented in the previous point concerning the structural inadequacy of TIM’s organizational structure. In the case referred to in File No. 444902, a particularly serious issue emerges: the partner XX, already rated as “INADEQUATE” by TIM in November 2023 due to extremely serious violations, continued to enter unlawful contracts into the system. The fact that the agency was kept operational through mere “documentary monitoring” constitutes a flagrant violation of Articles 28 and 32 of the Regulation.

- Files Nos. 513320 and 518841: The records show that partner XX uploaded activation orders to TIM’s corporate systems following multiple unlawful contacts. The fact that the contracts were not finalized or that the User exercised the right of withdrawal pursuant to Art. 16 of the Code of Conduct does not negate the occurrence of the violation. The right of withdrawal pertains to the contractual sphere, not to the lawfulness of data processing, which remains fundamentally flawed due to the lack of an appropriate legal basis.

- Case No. 557370: The Company’s defense, which seeks to characterize the offer of the “TIM Vision” service as a complimentary gift as a service communication based on Art. 6(1)(b) of the Regulation (performance of a contract), cannot be accepted. While acknowledging that the communication in question is intended to inform the customer of the possibility of taking advantage of a benefit linked to the existing contractual relationship, it should be noted that the aforementioned provision of the Regulation makes the lawfulness of the processing contingent upon the strict requirement that it be “necessary” for the performance of the contract. In the present case, it is clear that free subscription to “TIM Vision” is in no way necessary for the performance of the complainant’s telecommunications contract. The offer of this additional product pursues a clear commercial purpose within the meaning of Article 130, paragraphs 1 and 2, of the Code. In fact, this category includes any initiative—even one that is not strictly advertising—aimed at promoting one’s own products or services and building customer loyalty as part of a broader marketing strategy. Therefore, such a communication required the prior and specific consent of the data subject pursuant to Article 130 of the Code. Since the User denied such consent, the communication is unlawful.

TIM’s objection regarding the “initial defense” nature of the brief filed for certain case files is also irrelevant, given that it serves as an appropriate means of ensuring the effectiveness of the adversarial principle.

The data controller’s accountability is definitively confirmed by the glaring statistical discrepancies regarding monthly activation volumes (e.g., November 2024), as previously mentioned.

Cross-referencing the log files revealed extremely significant anomalies: Agency XX, despite reporting approximately 6,000 leads, made over 16,000 contacts; Agency XX generated over 22,000 contacts with an activation rate of less than 4%.

These mathematical findings are sufficient to fundamentally undermine the presumption of the data controller’s good faith. From a logical and legal perspective, the generation of a genuine lead—which, by definition, should presuppose a targeted and informed request from the User—is incompatible with such a large volume of unsuccessful or rejected contact attempts. Faced with statistically anomalous conversion rates and volume discrepancies of this magnitude, the Company, in accordance with the principles of accountability and security (Articles 5, 24, and 32 of the Regulation)—should have initiated verification measures, upon the outcome of which the immediate blocking of traffic flows and the activation of automated alerts could have been implemented. The fact that it passively accepted such volumes of traffic demonstrates a complete lack of substantive audits regarding the appropriateness and operational methods of the agencies designated as processors, effectively endorsing the use of “phantom” call centers.

While this Authority views positively the Company’s stated intent to strengthen its monitoring controls through the introduction of specific anomaly indicators (so-called “triggers”) designed to initiate second-level verifications, cannot, however, refrain from censuring the conduct exhibited to date and the related violations ascertained with regard to past processing activities.

In light of the foregoing considerations, it must be deemed proven that the data controller has structured and maintained an organizational and IT system that is unsuitable for ensuring the lawfulness of the processing operations carried out by its sales chain.

TIM is therefore found to have violated the following regulatory provisions:

- Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having allowed the carrying out of abusive promotional contacts—disguised as false requests for a callback—in the absence of prior, free, and specific consent;

- Article 5, para 2, of the Regulation: for violating the principle of accountability, by failing to adopt control systems capable of ensuring and demonstrating effective oversight of the lawfulness of its sales network’s operations;

- Articles 24, 25, and 28 of the Regulation: for failing to adopt appropriate technical and organizational measures from the design phase of the processing (data protection by design), suitable for preventing the upload of contracts originating from unregistered or disguised phone numbers and for ensuring compliance with the mandatory instructions provided to partners;

- Art 32 of the Regulation: for the insufficiency and inadequacy of security measures relating to consent collection processes and order-upload systems.

4.4. On the Inadequacy of Opt-Out Procedures and Obstacles to the Exercise of Rights

Having examined the defense brief submitted by TIM, this Authority finds that the arguments presented therein are insufficient to rebut the findings set forth in the notice of violation, thereby confirming the existence of systemic and organizational shortcomings in the handling of requests from data subjects (with the exception of the specific case referred to in file no. 519239). 

With regard to the reports concerning TIM’s failure to comply with requests from data subjects to exercise their data subject rights, the following observations are made. Regarding:

- File No. 478291: The justification provided by the Company regarding the “technical time required” to align its information systems is insufficient to justify the continued sending of the disputed promotional communications. The fact that such communications continued to be sent for more than four months after the objection was filed highlights a clear inadequacy of the technical and organizational measures adopted by the controller. A mere formal response within 30 days is ineffective unless accompanied by a timely and substantive cessation of the processing.

- Case Nos. 438663 and 517806: The data subjects’ use of corporate communication channels that are allegedly “inappropriate” (certified email [PEC] for unsolicited telemarketing or an email address belonging to a Data Protection Officer [DPO] who is in the process of leaving the company) and any “technical anomalies” do not invalidate the request. It is the data controller’s responsibility, in accordance with the principle of accountability, to establish internal document workflows capable of intercepting and correctly routing privacy requests received at its official contact addresses.

TIM is therefore found to have violated the following provisions:

- Articles 17 (Right to erasure) and 21 (Right to object) of the Regulation, for failing to act on the requests of data subjects;

- Articles 6(1), subparagraph (a) of the Regulation and Article 130, paragraph 2, of the Code, in that the sending of further promotional communications, following an objection or a request for erasure, occurred in the absence of valid consent and, therefore, lacked a proper legal basis.

With regard to the complaints referred to in case files nos. 438663, 517806, 443623, 448740, and 557370 concerning the implementation of cumbersome opt-out procedures—which make the revocation of consent contingent upon access to the MyTIM (MyTIM) or the use of specific applications, it is noted that this mechanism is in clear contrast to the principle enshrined in Art 7, para 3, of the Regulation, according to which the withdrawal of consent must be as easy as giving it. The Company’s reference to Article 12(6) of the GDPR (the need to verify the identity of the requester) appears irrelevant and self-serving. Digital authentication cannot result in a disproportionate burden that effectively precludes or discourages the exercise of this right, in clear violation of Article 12(2) of the Regulation.

With specific reference to cases nos. 443623 and 448740, the fact that one of the data subjects (case no. 448740) was a TIM customer and that both data subjects ultimately acted independently or contacted this Authority directly does not retroactively remedy the original shortcomings of the opt-out system, which imposed undue obstacles that required external intervention or extended timeframes to be resolved.

Only in one case, file no. 519239, does the Authority agree with the argument and legal framework presented by TIM. An examination of the documentation on file revealed that, in this specific case, TIM’s sending of promotional emails was based on valid, prior consent expressly given by the data subject upon signing a “business” contract. The failure to complete the unsubscribe procedure, on the other hand, is attributable to a clerical error on the part of the complainant. The case in question is therefore deemed closed.

In light of the foregoing, TIM is found to have violated the following provisions:

- Article 12, para 2, of the Regulation, for failing to facilitate the exercise of data subject rights;

- Articles 15 through 22 of the Regulation, for violating the applicable provisions regarding the exercise of rights, thereby rendering the request for objection or erasure ineffective;

- Art 24 of the Regulation, for failing to implement adequate technical and organizational measures to promptly and effectively accommodate the wishes of data subjects.

4.5. Regarding the failure to respond, or the late or inadequate response, to requests from data subjects

The defense arguments regarding the residual and purely statistical nature of the delays, although supported by quantitative data from 2025, do not negate the unlawfulness of the individual violations alleged. The Regulation is designed to protect the fundamental rights and freedoms of individuals; therefore, the statistical efficiency of the system does not constitute a defense for violations committed to the detriment of individual complainants. This circumstance, if duly proven, may nevertheless be taken into consideration—not for the purpose of establishing the violations, but rather when determining the penalty—as an indicator of the overall adequacy of the organizational structure established by the Data Controller pursuant to Article 83, para 2, of the Regulation.

Furthermore, there has been a distorted and non-compliant use of so-called “interim responses.” Article 12, para 3, of the Regulation permits an extension of the original 30-day deadline by up to an additional two months only in cases of proven complexity, but requires the Data Controller to inform the data subject of such an extension and the reasons for it within one month of receiving the request.

- File No. 514826: A response time of 88 days cannot be justified by the mere transmission of an interim response if it does not meet the formal and substantive requirements for an extension set forth in Art. 12, para. 3. The need for cross-checking does not justify exceeding the mandatory maximum time limits.

- Files Nos. 425095 and 513320: The accumulated delays of 120 and 51 days, respectively, demonstrate the ineffectiveness of the response procedures. It should also be noted that, with regard to File No. 425095, contrary to the Company’s claims, the “final confirmation” was not received on February 24, 2025, at all. In that vague and evasive communication, TIM merely confirmed that the order had been entered into TIM’s systems by a “sales network agency” without, however, disclosing its name and citing, in this regard, the “particular complexity of such operations.” It was not until March 26, 2025—120 days after the initial request and only after the Authority had launched its investigation—that the Company complied with the complainant’s request by informing her that the data had been processed by Agency XX. The 120-day delay exceeds even the maximum and absolute three-month deadline (30 days plus a two-month extension) granted by European legislation for cases of extreme complexity. The fact that the contacts originated from third parties or business partners reaffirms TIM’s accountability for selecting and supervising the operations of its sales chain, as the Data Controller cannot shift the blame for the inefficiencies of its own organizational and control structures onto the data subject.

- Cases Nos. 500303 and 520955: The distinction made by TIM between “contractual prerogative” and “right to privacy” is deemed valid. A request for erasure of an account and a request to reset one’s email password do not fully fall within the scope of exercising a privacy right. Case No. 500303 is therefore closed. However, with specific reference to case no. 520955, the clerical error in the IT classification system that resulted in the failure to respond to the complainant’s subsequent request regarding storage periods constitutes evidence of an organizational deficiency attributable to the Data Controller.

Consequently, TIM is found to have violated Articles 5(1)(a) and (2), as well as Articles 12, 15, 17, and 21 of the Regulation.

4.6. On the Procedural Objections Raised by the Company

Finally, the objections raised by the Company regarding the conduct of the preliminary investigation and, more generally, the proceedings at hand cannot be upheld.

4.6.1. Alleged Lapse of the Authority’s Power to Impose Sanctions

The arguments put forward by the Company regarding the alleged lapse of this Authority’s power to impose sanctions due to the expiration of the 120-day deadline for serving the notice of initiation of proceedings (pursuant to Article 166, paragraph 5, of the Code and Table B, point 2, of Regulation No. 2/2019, hereinafter also referred to as the “notice of charges”), are manifestly unfounded.

As a preliminary matter, it should be noted that the assertion that the 120-day period provided for in Regulation No. 2/2019 began to run on April 17, 2025 (i.e., the date of the so-called “Notice of Withdrawal of Reservations”).

The record shows that the preliminary investigation had by no means been concluded in April 2025: TIM itself subsequently submitted three Media Updates to this Authority (on July 4, July 31, and December 9, 2025, respectively), providing additional information on the systems and measures adopted by TIM that were the subject of the investigation. Furthermore, from April through December 2025, the Authority continued to receive hundreds of complaints against TIM regarding cases similar to those under investigation; in light of this, in October 2025, the Authority decided to issue additional requests for information regarding certain cases (see case files nos. 496215, 478291, 500303, 513320, and 514826).

Therefore, the Company’s argument—aimed at denying any procedural relevance to these submissions on the grounds that they were “spontaneous” and unsolicited, in order to invoke the expiration of the deadlines on September 15, 2025—appears specious and logically paradoxical. The party’s attempt to introduce new elements into the investigative file (which it itself expressly describes as “media updates” to the inspection reservations), implicitly asking the Authority to evaluate them, only to then argue that the Authority must disregard them for the purposes of calculating procedural deadlines. 

Since the preliminary investigation was still ongoing, the facts necessary to establish the violation could not be finalized until the most recent relevant document sent by TIM on December 9, 2025, had been received (recorded under ref. no. 174524 on December 16, 2025).

Even if one were to disregard the established case law of the Court of Cassation—which identifies the moment of determination not as the time of the actual receipt of the investigative documents, but rather as the time of their comprehensive evaluation—and were to assume (purely hypothetically) that the date of TIM’s last notice coincides with thethe actual “determination of the violation” pursuant to Regulation No. 2/2019—and thus considering December 9, 2025, as the starting point for the calculation—the 120-day period would have expired on April 8, 2026.

Recital 1 states that the notice of initiation of proceedings pursuant to Article 166, paragraph 5, of the Code was duly served on the Company on February 9, 2026 (i.e., two months prior to the deadline), it follows that the administrative action was fully timely and in strict compliance with the time limits imposed by applicable law.

In light of this chronological account, the Company’s invocation of the suspension mechanism provided for in Art. 7 of Regulation No. 2/2019 is clearly irrelevant. The provision in question, in fact, governs the suspension of a time limit that has already begun to run, making it contingent upon a specific prerequisite that differs from the one at issue: a formal request by the Authority to the applicant to provide “information, additional details, or clarifications” or to submit documents, with the resulting resumption of the calculation “from the expiration date of the deadline set for the requested compliance.” The reasoning set forth above, however, does not require the application of any suspensive provision, since it does not concern the suspension of a time limit already in progress, but rather the identification of the starting date from which the time limit itself begins to run. Since this deadline is extended based on the progressive consolidation of the investigative documents, it has in any case been amply respected; the reference to Article 7 therefore falls on a different logical-legal plane and is irrelevant to the matter in dispute.

It is also decisive to note that TIM’s three Media Updates were all received before the expiration of the 120-day period and the alleged exhaustion of the authority to impose sanctions (the first, dated July 4, for example, was received just 78 days after April 17).

Finally, the objection regarding the alleged illegality of the joint handling (aggregation) of multiple complaints or reports in the context of sanction proceedings is rejected. The consolidation of proceedings concerning similar cases or the same processing activities carried out by the same data controller is not only provided for in Art. 10, paragraph 4, of Regulation 1/2019, but also meets the criteria of sound administration, effectiveness, and cost-efficiency of administrative action enshrined in Law 241/1990, ensuring a comprehensive and consistent assessment of the alleged violations, while fully upholding the principle of proportionality in any determination of the amount of the penalty. This approach, moreover, serves as a safeguard for the controller itself: combining the cases into a single proceeding allows for the possible application of the absorption mechanism provided for in Art. 83, para. 3, of the Regulation, whereby, in the event of a violation of multiple provisions relating to the same processing or related processing operations, the total amount of the fine may not exceed that provided for the most serious violation. Had the same conduct been pursued separately, through the initiation of multiple independent penalty proceedings, the data controller would have been exposed to the risk of a far more severe overall outcome, as well as to a multiplication of the procedural and defense costs associated with managing multiple parallel investigations.

In light of the above considerations, the objections raised by TIM must be rejected in their entirety, and the full legitimacy of the Authority’s actions must be confirmed.

4.6.2. Alleged Violation of the Ne Bis in Idem Principle

With regard to the objections raised by the Company concerning alleged lis pendens and the violation of the ne bis in idem principle, the Authority considers the arguments to be entirely unfounded for the reasons outlined below.

The administrative proceeding concluded with Decision No. 183/2023—currently sub judice and in connection with which the court has ordered a court-appointed expert opinion (CTU)—is fundamentally distinct from the present investigation, as there is no identity between the parties, the subject matter sought, and the cause of action: the case files under review, the data subjects involved, the specific situations analyzed, and the contested processing operations are, in fact, different.

The previous decision concerned the use of contact lists for promotional purposes and outbound calls by partners, a practice that has now been almost entirely abandoned; the current proceeding, on the other hand, focuses on new methods of customer acquisition, based on requests for follow-up (leads) made by Users after viewing offers on digital channels (websites, social media, or comparison sites).

The fact that a court-appointed expert assessment on corporate governance is pending does not, therefore, grant the Company an “absolute license of lawfulness” for the entirety of the processing activities carried out, nor does this circumstance exempt the Authority from its duty to open new proceedings and initiate new investigations in response to new facts that may constitute separate violations of data protection regulations.

Even where a formal overlap is found between the contested regulatory provisions, there is no substantive overlap, as demonstrated by the application of the principle of accountability (Art. 5(2) of the Regulation) in the two proceedings: in Decision No. 183/2023, the violation of Article 5(2) was established in close connection with the lawfulness of the original data collection and the initial contact with the potential customer, whereas in today’s decision, the violation concerns not only the lawfulness of the data, but also structural organizational deficiencies, critical issues in the security of processing, and specific omissions in the design of the system of controls over the data chain.

The principle enshrined in Art. 5(2) of the Regulation is, moreover, of general application and allows the Authority to impose accountability sanctions on the part of the data controller relating to factual and legal situations that are profoundly different from one another: the processing of personal data, in fact, consists of a multitude of operations and involves numerous actors and therefore cannot be assessed as a single block that is either unambiguously lawful or unlawful.

The Authority has full discretion to focus its actions on specific segments and procedures, particularly when dealing with complex organizational structures: addressing the same data controller on multiple occasions does not constitute a violation of the ne bis in idem principle, but rather a scenario expressly provided for by the Regulation, whose Article 83(2), para. subparagraphs (e) and (i), requires the Authority to take into account “any relevant previous infringements” and compliance with prior measures adopted “in relation to the same subject matter.”

Therefore, the adoption of corrective and sanctioning measures in quick succession against the same company, while examining distinct aspects and processing operations, falls within the full and legitimate exercise of the Authority’s institutional duties.

5. CONCLUSIONS

In light of these considerations, the issues raised in the notice initiating the proceedings pursuant to Article 166 of the Code are confirmed, as the statements made during the preliminary investigation and the defenses raised are insufficient to rebut the findings made by the Office.

Therefore, the Authority finds TIM S.p.A. accountable for the following violations:

a. Articles 24, 25, and 28 of the Regulation, for having implemented technical and organizational measures that were inadequate to ensure, from the design stage, that processing is carried out, in every respect and at any stage and/or level, in accordance with the Regulation, including with regard to processing carried out by data processors;

b. Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having contacted or allowed third parties to contact Users registered in the Do Not Call Registry without a valid legal basis;

c. Art 5(2) of the Regulation, the principle of accountability, for failing to adopt and/or demonstrate that it had adopted adequate control and oversight systems for the sales network;

d. Art 32 of the Regulation, for insufficient security measures regarding the collection of consents and the order-processing systems;

e. Articles 12(2) and (3) of the Regulation, for failing to facilitate the exercise of rights, for failing to respond to requests to exercise rights, or for responding with unjustified delay;

f. Articles 15 through 22 of the Regulation, for violating the applicable provisions regarding the exercise of data subjects’ rights.

The Authority orders the dismissal of cases nos. 519239 and 500303 for the reasons set forth in the grounds.

Having also established the unlawfulness of the Company’s conduct with respect to the processing operations under review, it is necessary to:

- to order TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to implement corrective measures in the customer follow-up procedure following requests submitted through the Company’s or its partners’ websites, in order to prevent the mass collection of phone numbers to be contacted and to ensure that consent to be contacted has been provided by the actual data subject;

- to order TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adopt adequate measures to monitor and supervise the activities of its partners and to ensure that promotional activities carried out on behalf of the Company are conducted in full compliance with personal data protection regulations;

- order TIM S.p.A., pursuant to Art 58, para 2, subparagraph d) of the Regulation, to adapt the procedures designed to ensure the exercise of the rights under Articles 15–22 of the Regulation, in order to prevent or at least significantly reduce instances of failure to respond, delayed responses, and systematic extensions of deadlines;

- issue an injunction, pursuant to Article 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, to impose on TIM S.p.A. the administrative fine provided for in Art. 83, paragraphs 3 and 5, of the Regulation. 

6. INJUNCTION ORDER

The violations indicated above require the issuance of an injunction pursuant to Article 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981 against TIM S.p.A.; since, in the present case, a violation of Articles 5, 6, 7, 12, 15 through 22, 24, 25, 28, and 32 of the Regulation, as well as Article 130 of the Code, have been established, the provision set forth in Article 83, paragraphs 3 and 5, of the Regulation applies.

In determining the maximum statutory amount of the monetary penalty, TIM’s argument that only “revenue related to contracts concluded through leads generated by digital agencies” should be considered cannot be accepted: the Regulation itself expressly stipulates that the “total annual worldwide turnover of the preceding financial year” must be used as the reference (Art. 83 para. 5 of the Regulation). In this regard, see also Recital 150 of the Regulation on the concept of an enterprise, according to which “where administrative fines are imposed on enterprises, enterprises should be understood as defined in Articles 101 and 102 TFEU for these purposes.” Therefore, based on current legislation and in accordance with previous decisions adopted by the Authority, reference must be made to the TIM Group’s revenue, as derived from the most recent available financial statements (December 31, 2025). It follows that, in the case at hand, the maximum statutory fine is determined pursuant to Art. 83, paragraphs 3 and 5, of the Regulation at 549,360,000.00 euros.

In determining the amount of the fine, the factors set forth in Article 83, para 2, of the Regulation must be taken into account.

In the case at hand, the following factors are relevant:

- as a mitigating factor, the moderate severity of the violations (Article 83, para 2, subparagraph (a) of the Regulation), taking into account the short duration of the violations and the small number of data subjects involved;

- as an aggravating factor, (Article 83(2)(b) of the Regulation) the significantly negligent nature of the violations, committed by a leading operator in the telecommunications sector—a company that possesses the necessary know-how to properly implement the provisions regarding data protection;

- as a mitigating factor, the measures adopted by the Company (monitoring of its partners’ activities, which also led to the termination of the relevant contracts; introduction of IT and organizational procedures) during the investigation to mitigate the harm, even potential harm, to data subjects (Article 83(2)(c) of the Regulation);

- as an aggravating factor, the instance of the Company’s accountability (Article 83, para 2, subparagraph d), of the Regulation), taking into account the specific characteristics of the telemarketing sector—which is characterized by a large and pervasive “underground” market—and the risks posed to the personal data of customers and potential customers;

- as an aggravating factor (Article 83(2)(e) of the Regulation), the numerous prior violations, including specific ones, committed by the Company;

- as a mitigating factor (Article 83(2)(f) of the Regulation), the Company’s high instance of cooperation, evidenced by the fact that TIM S.p.A. provided the Data Protection Authority—including during the course of the inspections—with detailed responses, supplying a comprehensive set of information that enabled a thorough assessment of the entire range of processing activities;

- as a further mitigating factor (Article 83(2)(g) of the Regulation), the fact that the violations did not involve special categories of data within the meaning of Article 9 of the Regulation;

- as a mitigating factor (Art. 83(2)(j) of the Regulation), compliance with the code of conduct for telemarketing activities;

- as a mitigating factor (Article 83(2)(k) of the Regulation), the substantial investments made by the Company to implement control procedures throughout the sales chain aimed at minimizing unlawful conduct.

Based on all of the above factors, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Art. 83(1) of the Regulation, it is deemed appropriate to impose on TIM S.p.A. an administrative fine of 9,516,000.00 euros, equal to 1.7% of the maximum statutory fine.

In the case at hand, it is deemed appropriate to impose the additional sanction of publishing this decision on the Data Protection Authority’s website, as provided for in Art. 166, paragraph 7 of the Code and Art. 16 of the Authority’s Regulation No. 1/2019, taking into account the nature of the processing operations, as well as the risks to the data subject rights and freedoms.

Finally, the conditions set forth in Art. 17 of Regulation No. 1/2019 regarding internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, are met.

NOW THEREFORE, THE DATA PROTECTION AUTHORITY

- pursuant to Article 57(1)(a) and (f) of the Regulation, declares the processing of personal data carried out by TIM S.p.A., in the person of its pro tempore legal representative, with registered office in Milan, Via Gaetano Negri 1, Tax ID 00488410010, for violating Articles 5, 6, 7, 12, 15 through 22, 24, 25, 28, and 32 of the Regulation, as well as Article 130 of the Code, as set forth in the reasoning;

- orders TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to implement corrective measures in the customer follow-up procedure following requests submitted through the Company’s or its partners’ web pages, in order to prevent the mass submission of phone numbers for follow-up contact and to ensure that consent for such contact has been provided by the actual data subject;

- orders TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adopt adequate measures to monitor and supervise the activities of its partners and to ensure that promotional activities carried out on behalf of the Company are conducted in full compliance with personal data protection regulations;

- orders TIM S.p.A., pursuant to Art 58, para 2, subparagraph d) of the Regulation, to adapt the procedures designed to ensure the exercise of the rights under Articles 15–22 of the Regulation, in order to prevent or at least significantly reduce instances of failure to respond, delayed responses, and systematic extensions of deadlines;

- orders TIM S.p.A., pursuant to Article 58, para 1, subparagraph (a) of the Regulation and Article 157 of the Code, to notify the Authority, within thirty days of the service of this order, the steps taken to implement the measures imposed;

ORDERS

TIM S.p.A., in the person of its pro tempore legal representative, with registered office in Milan, Via Gaetano Negri 1, Tax ID No. 00488410010, to pay the sum of 9,516,000.00 euros (nine million five hundred sixteen thousand/00) as an administrative fine for the violations set forth in the grounds of this decision, noting that the offending party, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by complying with the requirements set forth and paying, within thirty days, an amount equal to half of the penalty imposed.

ORDERS

the aforementioned Company, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of 9,516,000.00 euros (nine million five hundred sixteen thousand/00), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the Authority will take the necessary enforcement measures pursuant to Art. 27 of Law No. 689/1981.

ORDERS

a) pursuant to Article 154-bis of the Code and Article 37 of the Data Protection Authority’s Internal Regulation No. 1/2019, the publication of this order on the Data Protection Authority’s website;

(b) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Internal Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website;

c) pursuant to Article 17 of the Authority’s Internal Regulations No. 1/2019, the entry in the Authority’s internal register, as provided for in Article 57, para 1, letter u) of the Regulation, of the violations and the measures adopted;

Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the place where the controller of personal data resides, or, alternatively, with the court of the place of residence of the data subject, within thirty days from the date of notification of this decision, or within sixty days if the appellant resides abroad.

Rome, July 23, 2026

THE CHAIRMAN
Stanzione

THE RAPPORTEUR
Stanzione

THE SECRETARY GENERAL
Montuori

SEE ALSO Press Release of July 31, 2026

[Web Doc. No. 10277005]

Decision of July 23, 2026

Register of Decisions
No. 556 of July 23, 2026

THE DATA PROTECTION AUTHORITY

AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General;

HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”);

HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003, hereinafter the “Code”);

HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”);

HAVING REGARD TO the documentation on file;

HAVING REGARD TO the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801);

RAPPORTEUR: Prof. Pasquale Stanzione;

1. FACTS AND PRELIMINARY INVESTIGATION CONDUCTED

1.1. Origin of the Preliminary Investigation

The Authority, in exercising the powers set forth in Articles 157 and 158 of the Code, initiated an inspection of TIM S.p.A. (hereinafter “TIM,” the “Company,” or the “Data Controller”), in collaboration with the Special Unit for Privacy Protection and Technological Fraud of the Guardia di Finanza, following the receipt of numerous complaints and reports, including those submitted by a correspondent for a well-known television program. 

In a nutshell, the reports highlighted a phenomenon already known to the Authority, characterized by the activities of fraudulent call centers that make promotional calls on behalf of TIM using phone numbers outside the Company’s official sales network. This conduct is aimed at the unlawful collection of users’ personal data; users, under the mistaken belief that they are speaking with an authorized TIM agent, provide this information and sometimes sign up for promotional offers.

Specifically, among the operational schemes recently implemented by these agencies and reported by complainants is the following:

a) Receipt of unsolicited calls on phone numbers duly registered with the Public Do Not Call Registry (hereinafter “RPO”) from telephone operators who, using caller ID spoofing techniques, propose the activation of TIM offers or services;

b) sending data subjects, via SMS, a hyperlink to a webpage of an official partner in the TIM sales network, containing a form that the User is invited to fill out to submit an independent request for a callback (a so-called “Lead”);

c) subsequent contact with the data subject—based on the (fictitious) request generated via the web—by the call center, this time using a phone number duly registered in the Register of Communications Operators (hereinafter “ROC”), in order to generate an apparently legitimate flow of calls and a formally compliant contract formation process.

1.2. Preliminary Investigation Conducted

Based on the information provided in the reports, and in parallel with the investigations conducted in relation to other reports and complaints, the Office requested that TIM provide information necessary to obtain a complete picture of the various critical issues identified by the reporters and complainants.

Through the inspection and preliminary investigation conducted regarding the Company, it was possible to obtain a significant amount of information and documents, which were made available to the Authority by the Guardia di Finanza via letters dated March 26 and 27, 2025, Ref. No. 442/25, and subsequently supplemented by notes Ref. No. 54010 dated April 18, 2025, Ref. No. 55188 dated April 23, 2025, Ref. No. 95514 dated July 7, 2025, Ref. No. 108311 dated August 4, 2025, and, most recently, Ref. No. 174524 dated December 16, 2025.

2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND PENALTY MEASURES

2.1. Findings of the Preliminary Investigation and Initiation of Proceedings

Based on the evidence gathered during the activities described above, by a notice dated February 9, 2026 (Ref. No. 18734), served in accordance with Article 166, paragraph 5, of the Code and reproduced in full herein, the Office initiated proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation against the controller, inviting the latter to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981).

The alleged violations are detailed below.

2.1.1. Verification procedures regarding lead forms collected by digital agencies or on the TIM website—ex officio investigation

During the inspection, initiated ex officio against TIM, certain critical issues emerged regarding the procedures for acquiring personal data (so-called “leads”) collected through partner digital agencies or directly from the Data Controller’s website. In particular, there was a complete lack of mechanisms to verify the actual ownership of the phone numbers provided in the online data collection forms, thereby exposing data subjects to the risk of unsolicited contact.

In order to remedy the irregularities identified and in accordance with the principle of accountability (pursuant to Art. 5, para. 2, of the Regulation), during the course of the investigation—through submissions filed in the months following the inspection— the Company stated that it had implemented an automated preventive verification system, based on an M2M integration with the central TIMCO system.

Specifically, the new procedural framework is based on an opt-out mechanism via SMS: upon entry of the lead, the data subject receives a notification message and has a 5-minute window to deny ownership of the contact information or revoke consent (the so-called “right to change one’s mind”). TIM has also adopted additional technical and organizational measures to protect data subjects, including: (i) anti-phishing measures: implementation of communications sent exclusively via certified aliases and transparent URLs that can be uniquely traced back to the Data Controller’s official domain; and (ii) anti-fraud systems (IP control): the introduction of an automated blocking system designed to prevent the submission of multiple requests from the same IP address within a 15-minute time interval, specifically aimed at neutralizing and countering the mass upload of personal data via computer applications (so-called “bots”).

With regard to the system’s operational effectiveness and the progress of the aforementioned infrastructure, the Data Controller submitted additional documentation (Ref. No. 174524 dated December 16, 2025) certifying that the system had undergone final testing, with the full and final rollout scheduled for January 31, 2026.

While the Office views the Data Controller’s efforts to comply favorably, it has nevertheless notified the Company of an alleged violation of Article 25, para 1, of the Regulation, for failing to adopt adequate technical and organizational measures to ensure, from the design stage onward (“Data Protection by Design”), that processing was carried out in accordance with the principles of the legislation at every stage.

With specific regard to the aforementioned opt-out measure, the Office deemed it structurally unsuitable for protecting individuals whose phone numbers are entered into forms without their knowledge. In fact, these individuals receive an unsolicited text message containing an invitation to click a link to block future contacts; in this context, a procedure requiring prior confirmation of consent to be contacted again (opt-in) appears to be more appropriate.

During the year 2025, the Authority received numerous reports and complaints (approximately 7,000 complaints) concerning the receipt of unsolicited and unauthorized promotional communications on behalf of TIM. Some of these reports, which were initially the subject of separate investigations, were subsequently consolidated into a single main proceeding for the purpose of unified handling, given the evident systemic and structural nature of the alleged conduct.

A first and substantial group of complaints relates directly to TIM’s overall management of its data assets. The inspection and the findings of the preliminary investigation revealed that the Company, despite having made efforts and invested financial and organizational resources to combat the phenomenon of so-called “unknown calls,” it implemented control systems across the entire data collection “chain” that proved to be entirely unsuitable and deficient in many respects.

In particular, the investigations revealed that TIM had engaged third parties to process personal data without conducting the necessary preliminary checks to ensure compliance with the safeguards required by the GDPR, and without adopting adequate organizational measures to constantly monitor compliance with data protection regulations by its sales network.

The preliminary investigation made it possible to obtain documentary evidence (including screenshots extracted from the company’s systems) proving that commercial activation orders were entered into the company’s databases following unlawful telephone contacts. These abusive promotional calls originated from numbers not registered with the ROC and were directed, in many cases, at subscribers duly registered with the RPO. The unlawful conduct can be attributed to official TIM business partners, specifically the sales agencies XX, XX, XX, and XX.

The modus operandi adopted by these partners involved initiating sales processes through preliminary telephone contacts made without any consent whatsoever and using untraceable or altered (spoofed) phone numbers. Subsequently, in order to artificially mask the unlawful origin of the contact, the partners asked the data subjects to click on a specific link received via SMS or messaging services. This operation was designed to generate a fictitious, independent request for follow-up contact (lead), intended to “clean up” the data trail vis-à-vis the parent company. Consequently, the partners reported to TIM that they had acted in response to a spontaneous request from the User through regular channels, concealing the actual and abusive telemarketing activity carried out beforehand.

a) Review of Individual Investigation Files

In order to outline the objective scope of the violations identified, the findings regarding the individual files examined by this Authority are set forth below; these findings confirm the ineffectiveness of the Company’s compliance controls.

- File No. 425095: During the inspection, it emerged that certain orders in the name of the data subject, entered into the company’s systems by TIM’s partner XX, were listed as resulting from spontaneous online requests for follow-up contact regarding leads and subsequent regular phone calls. The investigation revealed a completely different reality: the contacts did not stem from the User’s initiative but represented the final stage of repeated and persistent abusive promotional calls originating from unregistered numbers (including WhatsApp accounts improperly bearing the Company’s logo). TIM’s preventive control and ex post monitoring systems proved inadequate, as they recognized only the “cleaned-up” calls that occurred after the generation of the fictitious leads as valid, ignoring the entire preceding unlawful phase. The structural inadequacy of the controls is confirmed by the fact that, despite hundreds of thousands of contacts, the Company detected only minor discrepancies and never reported any major issues involving the agency in question. 

- Case Nos. 496215 and 437668: The complainant filed a complaint with the Public Prosecutor’s Office, alleging that he had received automated calls on behalf of TIM and that leads were generated through links sent via WhatsApp. Following the complaint, the Data Protection Authority sent a request for information to TIM. The case files confirmed that numerous unlawful contacts had been made to promote TIM services using spoofed phone numbers by agencies within the company’s sales network. Specifically, the violations were attributed to the actions of XX in connection with an activation order (file no. 496215) and to the actions of XX (file no. 437668). In this case as well, the company’s information systems architecture processed the contracts without detecting the illegality of the preceding data processing activities.

- File No. 434470: On February 18, 2025, the complainant, acting on behalf of third parties, reported automated calls to a subscriber registered with the RPO on behalf of TIM, originating from numbers not registered with the ROC. During the inspection, evidence was obtained regarding an activation order entered into TIM’s information systems by the business partner XX. The documentation on file unequivocally confirmed that the subscription to the service originated from abusive commercial contacts carried out using CLI spoofing techniques, thereby circumventing the Company’s Tracking and verification systems.

- Case No. 444902: The complainant reported, on behalf of a third party, an automated call received on January 23, 2025, on a number duly registered with the RPO to promote TIM services. Following an initial expression of interest, the data subject was contacted again by a self-proclaimed consultant via a WhatsApp profile bearing the TIM logo to provide contract details. To complete the subscription, the data subject was asked to click on a link received via SMS from another untraceable number. This link led to a web page where data was entered to artificially generate an independent request for a callback (Lead). The investigation revealed an activation order processed and entered by TIM’s official partner XX. In the system, the transaction appeared legitimate and resulted from a “Lead” associated with the data subject’s account. The actual facts, however, contradicted the findings of TIM’s management portal: the contact did not stem from a spontaneous request by the customer, but was the result of multiple unauthorized contacts that occurred on the same day and an SMS containing the link to generate the false request. A particularly serious issue emerged in the fact that Partner XX had already been subject to Level II audits by TIM in November 2023, which had concluded with a rating of “INADEQUATE.” Extremely serious violations had been identified, such as the processing of data by an unauthorized subcontractor and the use of real leads in a test environment. Nevertheless, TIM had limited itself to issuing a formal warning and implementing a paper-based monitoring system that proved to be completely ineffective.

- File No. 513320: In this case as well, the order was entered into TIM’s official systems by a TIM partner, XX., confirming the vulnerability of the Company’s acquisition channels to data flows of illicit origin. Upon discovering the unlawful processing of her data through unauthorized channels, the complainant subsequently requested that TIM cancel the order and the contract, as well as identify the partner responsible for the calls. Following the Data Protection Authority’s request for an investigation (October 3, 2025), TIM responded to the complainant on October 22, 2025, and to the Authority on October 23, 2025.

- File No. 518841: In a complaint filed on September 9, 2025, the complainant alleged that he had been deceived by an individual who falsely claimed to be an agent of the competitor “XX,” who fraudulently induced him to switch to TIM by providing false technical information. The case files provided further evidence that personal data unlawfully obtained from unidentified third parties acting on behalf of the Company had been entered into TIM’s information systems via activation orders. The complainant expressed concern that unidentified individuals had obtained all of his personal and sensitive data (including his address), creating a high risk of retaliation and further unlawful use of such data.

- Case No. 557370: The complainant reported receiving unsolicited promotional emails, noting that he had refused to give consent for marketing purposes from the time the contract was signed and on every subsequent occasion. The documentation included in the case file revealed that TIM had sent promotional communications to the data subject without prior and valid consent.

b) Analysis of Aggregated Data and Obvious Discrepancies

The structural inadequacy of the compliance and monitoring system established by TIM emerged unequivocally from the statistical analysis and the cross-referencing of log files with the monthly activation volumes provided by the Company itself, with particular reference to the month of November 2024.

Operational data related to sales agencies reveal glaring inconsistencies that should have prompted the Company to immediately block the data flows and trigger security alerts:

Sales Partner Reported Leads Contacts Made Volume Discrepancy Conversion Rate / Outcome

XX 17,388 22,242 +4,854 contacts compared to leads Contract activation rate < 4%

XX 5,758 5,919 +161 contacts compared to leads 80% of Users unreachable; activation < 10% (509 orders)

XX 6,075 16,102 +10,027 contacts compared to leads Response rate of 1/3 (5,904); activation at 11% (708 orders)

 

From a logical and legal standpoint, the generation of a lead presupposes an independent, targeted, and informed request by the individual User. Therefore, the presence of such an excess of contact attempts (over 10,000 more than the requests in the case of XX), combined with extremely low conversion rates (less than 4% for XX) demonstrates in re ipsa the inauthenticity of the lists and the unlawfulness of the preliminary contacts.

Added to this is a complete lack of criteria for qualifying and selecting agencies. TIM failed to verify that the partners’ workforce was appropriately sized in relation to the volume of contacts generated (over 20,000 contacts per month per agency, equivalent to approximately 1,000 calls per day). This organizational shortcoming made it impossible to detect in advance the use of automated calling systems (bots) or the outsourcing of services to unauthorized call centers operating under unauthorized subcontracting arrangements.

Following the in-depth investigations conducted in connection with case files nos. 425095, 496215, 437668, 434470, 444902, 513320, 518841, and 557370, the Authority charged TIM with the following violations:

- Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having made, or allowed third parties to make, promotional contacts with Users registered in the Public Do Not Call Registry without a valid legal basis;

- Art 5, para 2, of the Regulation, for violating the principle of accountability by failing to adopt adequate control and oversight systems for the sales network;

- Articles 24, 25, and 28 of the Regulation, for failing to adopt appropriate technical and organizational measures to prevent the use of disguised numbers and to ensure compliance with the instructions provided to Partners;

- Article 32 of the Regulation, for the insufficiency and inadequacy of security measures relating to consent collection processes and order-processing systems.

2.1.3. TIM’s Handling of Requests to Exercise Data Subject Rights

The findings of the preliminary investigation highlighted systemic issues in the controller’s handling of requests to exercise rights (pursuant to Articles 15–22 of the Regulation), attributable to two main areas of concern.

a) Obstacles to the exercise of data subject rights and inadequacy of opt-out procedures

A first group of cases concerned TIM’s failure to process requests by data subjects to exercise their data subject rights, as well as cumbersome and inadequate opt-out procedures.

Specifically:

- Case No. 478291: The data subject continued to receive communications for over four months after exercising the right to object, as the Company failed to update its systems (thereby keeping consent active) and to add the email address to the blacklist.

- Case No. 519239: The systematic sending of promotional communications without consent or a contractual relationship was contested, compounded by the failure to respond to certified emails (PEC) requesting erasure and by the malfunctioning of the opt-out link.

- Cases Nos. 438663 and 517806: The complainants reported that they continued to receive promotional communications despite explicit requests for revocation and erasure sent via certified email (PEC) to the address “TIMaltuofianco” or to the DPO. Both also reported that the unsubscribe link was ineffective, as it was subject to complex technical requirements (a malfunctioning login or mandatory registration).

With regard to the aforementioned cases, TIM was charged with violations of Articles 17 and 21 of the Regulation (for failing to comply with the requests of the data subjects), and Articles 6(1), para 1, subparagraph (a) of the Regulation and Article 130, paragraph 2, of the Code, for sending repeated promotional messages without a valid legal basis. 

With regard to the excessive complexity of the procedure for unsubscribing from mailing lists—which the complainants (case nos. 519239, 438663, 517806, 443623, 448740, and 557370—have complained is “cumbersome” to the point of creating undue obstacles for the data subject, TIM has been charged with violations of Articles 12, para 2 (for failing to facilitate the exercise of rights), and Articles 15–22 (for violating applicable provisions regarding the exercise of rights, rendering requests for objection or erasure ineffective) and Article 24 (for failing to implement adequate technical and organizational measures to promptly and effectively accommodate the wishes of data subjects).

A review of the case files revealed that TIM did not ensure the criteria of simplicity and immediacy required by Article 7, para 3, of the Regulation. On the contrary, it made unsubscription contingent on complex steps, such as interacting with virtual assistants, downloading specific applications, or the requirement to log in to the company’s Restricted Area. This last requirement constituted a prohibitive obstacle, especially for “non-customers” who lacked login credentials.

b) Failure to Respond, Delayed Response, or Inadequate Response to Data Subjects’ Requests

A second group of cases revealed non-compliance with the obligation to provide a timely response to data subjects, in violation of the provisions of the Regulation, including Art. 12(3).

With regard to cases nos. 425095, 513320, 500303, 520955, and 514826 concerning the failure to provide, delayed, or inadequate response to requests to exercise rights, it should be noted that Article 12 of the Regulation requires the data controller to respond to the data subject without undue delay and, in any event, no later than one month after receipt of the request. This deadline may be extended by two months only if necessary, taking into account the complexity and number of requests.

A review of the documents revealed the following:

- File No. 425095: The Company responded to the complainant’s request (seeking to know the identity of the partner who placed the orders) only on March 26, 2025, that is, 120 days after the initial request dated November 26, 2024.

- File No. 513320: TIM responded to the complainant’s request only on October 23, 2025—51 days after the request dated September 2, 2025 (after citing, on October 2, the “particular complexity” of the transaction).

- Case No. 500303: TIM responded to the two requests for erasure submitted by the complainant only on May 14, 2025—that is, 85 days after the request (dated February 18, 2025).

- Case No. 520955: It was determined that the Data Controller completely failed to respond to a request pursuant to Articles 15–22 sent via certified email (PEC), after the 30-day deadline had expired without a response.

- Case No. 514826: In response to a request for access aimed at determining the origin of the data used for promotional calls, the Company provided the data subject with a response that was merely partial and significantly delayed (88 days after receipt).

The circumstances described above constitute an alleged violation of Article 5, para 1, subparagraph (a), and para 2, as well as Articles 12, 15, 17, and 21 of the Regulation due to the delayed and inadequate response to requests for access, erasure, and objection.

3. THE COMPANY’S DEFENSES

3.1. TIM’s Proper Governance

In response to the Authority’s allegations, TIM filed its defense brief on March 26, 2026 (Ref. No. 47656 of March 27, 2026), noting the following.

First, TIM noted that, at the time of the inspection, the Company had adopted a governance model fully compliant with the requirements of the Code of Conduct for Telemarketing and Telesales Activities (finally approved by the Data Protection Authority on March 7, 2024; hereinafter the “Code of Conduct”). Consequently, TIM had developed a legitimate expectation regarding the fairness of its conduct and the appropriateness of the investments it had made.

Specifically, the Company emphasized that Codes of Conduct are “precisely accountability measures aimed at ensuring that data controllers strike a proper balance of interests, thereby relieving them, at least in part, of the need to prove their own accountability and the compliance of the measures adopted” (EDPB Guidelines 1/2019 on codes of conduct and monitoring bodies under the Regulation).

According to TIM, the Authority could have raised objections only in the event of a failure to implement the measures provided for in the Code of Conduct. Conversely, if technological developments had rendered those measures inadequate, it would have been the Authority’s responsibility (and not the Company’s) to intervene with general guidance or to request their update (pursuant to Article 40 of the Regulation).

Second, the Company noted that the calls in question were actually made from numbers outside the official TIM network and by third parties operating covertly. These entities acted in flagrant violation of company directives, using illegal practices such as CLI (Calling Line Identification) spoofing to conceal their identity.

TIM emphasized that combating this phenomenon cannot be effectively left to individual private operators alone, requiring systemic enforcement and regulatory measures (e.g., AGCom Resolutions No. 106/25/CONS and No. 271/25/CONS), which have so far proved only partially effective due to the adaptability of the illegal networks.

Third, following the findings of the inspection and as evidence of its due diligence, in order to further curb fraudulent conduct, TIM stated that it had enhanced its control system with extensive measures. Following the inspection, TIM strengthened its control system against fraudulent conduct on three distinct levels. On the contractual and legal front, it initiated disciplinary actions against non-compliant agencies, including the termination of contracts with 10 Consumer agencies. In terms of oversight, it established—under the coordination of the DPO—an extraordinary control system based on mystery shopping audits and the “Valutometro” scoring algorithm. Finally, on the technical and organizational level, the company has introduced real-time blocking of duplicate IP addresses, immediate SMS opt-out, the “STOP SPAM” feature on the MyTIM App, and the suspension of the “Refer a Friend” offer.

TIM argued that any penalty based on strict liability would be unlawful, citing Article 3 of Law 689/1980 and the case law of the CJEU (Cases C-683/21, C-768/21, C-807/21).

The Company noted that the case law of the Court of Justice is consistent in affirming that the Regulation excludes any instance of strict liability. The imposition of financial penalties requires specific proof that the conduct is attributable to the controller on the grounds of intent or negligence (Cases C-683/21, C-768/21, C-807/21).

According to the Company, it is undisputed that if the processor exceeds the instructions or acts for its own incompatible purposes, it assumes the status of an independent controller, thereby severing the link of liability to the controller.

The Company concluded by arguing that conduct beyond that already carried out cannot be held against it. The alleged violations stem from the independent and fraudulent actions of third parties who acted outside the scope of TIM’s control and instructions. Therefore, the Company urged the Authority to direct its inspection and enforcement activities directly toward the illegal agencies and call centers that constitute the “underground network,” since the client is free of any negligence or willful misconduct.

3.2. The Phenomenon of Leads

In its defense brief, the Company contested the Authority’s findings regarding the alleged inadequacy of the technical and organizational measures adopted, opposing any mandatory imposition of an opt-in model in place of the current opt-out system.

Specifically, TIM argued that any injunctive or prescriptive measure would be premature, citing the need for prolonged monitoring of the effectiveness of the new opt-out system (which had been implemented only a few days earlier), given that, to date, no complaints had been received from data subjects indicating that it was malfunctioning.

The Data Controller noted that neither the opt-in nor the opt-out would be effective tools for curbing the phenomenon of so-called “underground” telemarketing (illegal calls made by third parties outside the company’s scope). The Company further clarified that the risk of massive fraudulent entries of personal data is already adequately mitigated by the established procedures for IP address tracking.

According to the Company, any defect identified during the lead acquisition phase (such as a telephone contact initiated without an appropriate legal basis) would not affect the consent subsequently provided by the data subject, which would remain free and informed. In this regard, TIM emphasized that the finalization of contracts always requires an additional and specific expression of intent by the customer, distinct from and subsequent to the generation of the lead.

TIM pointed out that the opt-in standard is not an established practice in the current relevant market. In the Company’s view, the Authority’s mandatory imposition of this standard would result in an unjustified competitive disadvantage compared to other economic operators in the sector. 

Finally, appealing to the principle of loyal cooperation, the Company expressed its hope that an institutional dialogue would be initiated with the Authority, aimed at jointly identifying alternative security measures and governance safeguards, should the current system be definitively deemed unsuitable following the outcome of the preliminary investigation.

3.3. Promotional Contacts Without Consent

The Company noted that it had acted correctly in all contested cases by managing leads that, to the best of its knowledge, were valid, and that it could not have been aware of any unsolicited calls prior to the lead.

It was also clarified that:

- the phone numbers used for the unsolicited calls did not belong to the TIM network;

- the activation orders generated were never converted into valid contracts;

- in any case, the Company terminated its contractual relationships with the agencies in question, specifically XX, XX., XX., and, subsequently, XX.

3.3.1. TIM’s “Activation Orders” System

As a preliminary matter, TIM explained the technical and operational functioning, within its corporate systems, of the activation orders that are the subject of the Authority’s objections.

The purchase of a TIM service requires the prior creation of a so-called “activation order,” a preliminary step preceding the actual conclusion of the contract. This order is managed through the “CCC” sales system, which sales representatives access using their individual credentials (username and password).

In cases of remote sales, once the sales representatives have completed the necessary personal verification (confirming the potential customer is of legal age) and technical verification (service coverage at the requested location, for example, for landline and internet service), the potential customer has the opportunity, before finalizing the activation order, to provide and manage their consents regarding personal data protection, as well as to select the payment and subscription methods (choosing between Digital Confirmation or authentication via OTP).

With specific regard to privacy consents, the operator explains the privacy notices to the potential customer over the phone and records the preferences expressed during the call in the system. Consequently, before the order is formally issued, the computer system automatically sends a summary of the consents granted via email, which the data subject may freely and at any time modify.

Subsequently, the potential customer receives—again via email—an additional communication containing a summary of the commercial offer, the required contractual documentation, and the privacy notice regarding the processing of personal data. Only at this stage does the agent proceed to fill out the administrative section titled “Contact Type Tracking,” indicating the phone number used for contact and the source of the data (e.g., acquired via leads, internal TIM lists, etc.).

After receiving the aforementioned documentation, the potential customer chooses the method for finalizing the contract (OTP or Digital Confirmation). In the first case, the order is validated and issued only once the agent has received the confirmation code from the customer. In the case of Digital Confirmation, the order is considered confirmed only when the company’s systems record the User’s direct input.

The Company reiterated that, for the purposes of concluding the contract, the offer always arises from a customer request, and the contract is considered finalized only upon activation by TIM. It follows that receipt of the activation order identification code does not imply the automatic conclusion of the contract with TIM.

3.3.2. Analysis of Individual Investigation Files

With regard to the individual cases, TIM provided the following clarification.

- File No. 425095: TIM clarified that the calling numbers never belonged to the TIM network. Internal investigations revealed that three separate sales orders were generated in the complainant’s name following three contact requests submitted independently on the XX Digital Agency portal. Therefore, the Company found in its systems only a record of a validly created lead, the creation of which was not contested by either the data subject or the Authority. In any case, TIM terminated all contractual relationships with the aforementioned agency effective July 2025, and it has been verified that the three activation orders were never converted into valid contracts.

- File No. 496215: TIM highlighted the following: the disputed calls originated from numbers not assigned to the TIM network; the system showed a lead that had been correctly acquired through the aforementioned Agency XX (a partner with whom TIM has terminated its relationship); and the related activation order was never finalized into a contract. Regarding consent, the Company promptly sent the petitioner—at the same time the order was issued—a summary email so that the petitioner could review it and, if necessary, correct the preferences provided over the phone (it was noted, however, that only the consent for marketing purposes related to TIM products and services was marked as “YES,” while all other purposes were marked as “NO”). TIM therefore processed a lead that, to the best of its knowledge, had been acquired in full compliance with regulations.

- Case No. 437668: TIM noted, as a preliminary matter, that the defense brief constitutes the first defense submitted in the aforementioned case. The Company noted that the calling number does not belong to TIM. The documentation on file clearly showed that the complainant deliberately prolonged the conversation with the alleged operator in order to conduct an independent investigation, and not to activate a service. In fact, the contract was never concluded. The Company’s IT systems simply received a formally valid lead transmitted by XX; the Company had no way of foreseeing the existence of deceptive or disruptive conduct occurring earlier in the supply chain.

- File No. 434470: TIM noted that it became aware of the report exclusively during the Authority’s inspection operations, as the report was submitted by the complainant on behalf of third parties. The Company was able to identify the data subjects solely thanks to the activation order codes provided by the complainant. TIM represented that its systems showed the presence of a formally correct lead, provided by Digital Agency XX (with which TIM has terminated its contractual relationship). The applicant, having nevertheless continued the telephone conversation, initiated an activation order on February 6, 2025, which never resulted in the conclusion of a contract.

- File No. 444902: The company’s representative stated that the data subject complied with the follow-up procedure until she received an SMS link traceable to Digital Agency XX. The complainant then proceeded to enter the data for the sole purpose of revealing the identity of TIM’s business partner. In this case as well, TIM objected that no contract had been concluded, and following the aforementioned investigations, TIM immediately terminated its partnership agreement with XX.

- File No. 513320: TIM determined that the reported phone numbers were not in use by TIM or its sales network, nor were they registered with the R.O.C. The system recorded only one lead generated by Agency XX, which entered the activation order, which was subsequently canceled at the explicit request of the data subject. To ensure maximum protection for the user, TIM nevertheless recorded the marketing opt-out for the reported mobile line in its databases, even though the line was not registered on the TIM network.

- Case No. 518841: As a preliminary matter, TIM noted that the defense brief constitutes the first defense filed in this case. TIM confirmed receipt of a lead that was properly uploaded by Agency XX. Following contact, the data subject initially confirmed their intention to proceed (a circumstance documented in the complaint itself), but then exercised their right of withdrawal on September 14, 2025, requesting cancellation of the order—a request that was promptly honored and carried out by the Company. In response to the Authority’s finding regarding the use of unlawfully collected data, it was argued that TIM could not have been aware that the contract was preceded by a call made without first obtaining consent. The Company noted that it had acted in strict compliance with Article 16 of the Code of Conduct, promptly accommodating the customer’s subsequent change of mind.

- File No. 557370: As a preliminary matter, TIM pointed out that, in this case as well, the defense brief constitutes the first defense regarding the file in question and that it is not related to the creation of a lead. The Company noted that the User never received any marketing communications. The emails in question concerned exclusively contractual updates, specifically the right to a specific contractual benefit (the legal basis would be Article 6, paragraph 1, subparagraph b) of the Regulation), which provided for the TIM Vision service to be offered as a free gift during the Christmas season. Therefore, TIM did not send any promotional communications without consent, and no charges can be brought against TIM in relation to this specific case. Finally, regarding the opt-out procedure, it was noted that even if the petitioner had formally exercised that right, he would still have received the aforementioned service communications, given their strictly contractual and non-commercial nature (since consent for marketing communications had already been denied in advance and recorded in the system). 

3.3.3. Additional Measures Being Considered by TIM

To supplement the actions already underway, TIM has stated that it intends to tighten the selection process for digital agencies through a system based on specific checklists. The goal is to verify in advance the organizational adequacy of partners by requesting details on the number of resources deployed, operational capacity, prior experience, and the degree of compliance with privacy regulations, thereby eliminating undersized or inadequate entities.

The Company also intends to enhance its monitoring systems by establishing new “alert triggers” to initiate more in-depth checks (Level II audits). These alerts will be triggered both through the strategic use of post-activation surveys and through the identification of statistical anomalies, such as productivity that is disproportionate to the declared workforce or anomalous contact rates.

Finally, as an additional safeguard, TIM is considering extending the trial period for new partners. This measure would allow the company to have a longer period of time to promptly identify and address any issues or irregularities from the earliest stages of the partnership.

3.4. Handling Requests to Exercise Rights

TIM first noted that the handling of requests to exercise rights also falls within the scope of activities governed by the Code of Conduct. In particular, TIM’s handling of requests to exercise rights is governed by internal procedures that precisely define (i) the designated channels for receiving requests; (ii) the requirements for identifying the requester; (iii) the workflows to the relevant departments; (iv) response times; and (v) the procedures for tracking requests and updating blacklists.

3.4.1. TIM’s Timely Action in Response to Customers’ Requests to Stop Receiving Promotional Communications

Regarding the complaint concerning the failure to promptly comply with customers’ requests to revoke consent to promotional communications, the Company noted that its email promotional campaigns are directed exclusively at customers who have provided specific consent for marketing purposes and not at subscribers to newsletter services. TIM also had a representative state that it is in full compliance with Article 12, para 6 of the Regulation regarding the digital authentication measures required for access to the MyTIM Area, characterizing them as security measures necessary to verify the identity of the requester and to prevent the risk that third parties might interfere with the data subject’s profile by altering their intent.

Furthermore, data subjects have various channels available to exercise their rights and revoke their consent, such as writing to TIM’s institutional certified email (PEC), the DPO, or calling customer service, etc.

With regard to the specific individual cases, TIM noted the following.

- File No. 478291: The Company argued that its conduct was fair, having responded to the data subject’s request within the thirty-day deadline, confirming that the request had been received. TIM emphasized that the subsequent receipt of promotional communications was due exclusively to the technical time required for “specific system updates,” during which the Company nevertheless kept the User informed until the final opt-out. TIM contested the complainant’s assertion regarding the absence of prior contractual relationships, noting that the email address on file was duly registered as the contact information for a Business account with marketing consent that had been actively confirmed from the outset. The Company also noted that the failure of the opt-out procedure was due to repeated errors by the complainant, who entered his personal tax ID number instead of the one associated with the customer profile, causing the control systems to automatically reject the request.

- File No. 438663: The Company pointed out the complainant’s error in identifying the communication channel, as the complainant had submitted the request to a TIMaltuofianco corporate certified email (PEC) account specifically and exclusively designated to receive reports regarding the phenomenon of so-called “unsolicited telemarketing” carried out by third-party operators. The complainant’s error prevented the automatic processing of the revocation, which TIM fully complied with as soon as the circumstances were clarified following the transmission of the documents by this Authority.

- File No. 517806: The Company noted that the initial request was sent to a Data Protection Officer’s (DPO) email address that had already been formally decommissioned, preventing its proper registration. TIM clarified that a subsequent request sent to the institutional certified email address was not processed due to an unforeseen “technical anomaly” in the IT systems; however, the Company proceeded to definitively adjust the consents in accordance with the data subject’s wishes.

- Cases Nos. 443623 and 448740: TIM objected that the complainants never submitted formal requests to exercise their rights to the Company, having instead contacted the Data Protection Authority directly. The Company also refuted the alleged absence of a contractual relationship with one of the data subjects (Case No. 448740), confirming that she held multiple active lines. Finally, TIM noted that the complainants had in any case unsubscribed on their own through the company’s web portal.

- File No. 557370: The Company ruled out the commercial nature of the disputed emails, classifying them as communications regarding contract updates and the provision of free holiday benefits. TIM further clarified that the customer’s status had already been set to “marketing consent denied,” rendering the initiation of a revocation procedure materially unnecessary, and that the Company had in any case provided formal confirmation to the data subject.

3.4.2. Cases Characterized by Particular Complexity

TIM strongly contested the Authority’s assertion that the use of the extension of time limits provided for in Art 12, para 3, of the Regulation constitutes the Company’s standard operating procedure. The consolidated data for the year 2025 in the Consumer segment demonstrated the absolute effectiveness and resilience of the Company’s organizational processes: out of a total of 54,376 requests processed, 98.30% (equal to 53,449 requests) were resolved within the standard 30-day deadline. Cases where this deadline was exceeded represented a completely residual and statistical percentage (1.24% between 30 and 90 days and 0.47% beyond 90 days), attributable solely to particularly complex investigations (such as multi-system reconstructions, document verifications with third parties, and checks on external numbering systems). The Company also pointed out that identifying business partners and reviewing individual case files required extensive cross-checking across multiple application environments and complex external interactions, ruling out the notion of a “simple query” as hypothesized by the Authority.

With regard to the specific individual cases, TIM noted the following.

- File No. 425095: The access request (November 2024) required complex verification activities involving third parties and phone numbers not in use by the Company. TIM provided an interim response within thirty days, requesting identifying documentation in accordance with Art 12, para 6, of the Regulation. Once the investigation was completed, the Company sent its final response on February 24, 2025, confirming that the contacts in question were unrelated to its organization.

- File No. 513320: The request, aimed at identifying the source of an allegedly irregular sales contact, received an initial interim response within 30 days and a final response in October 2025. The investigation revealed that the order was placed and then canceled by a partner in the sales network. TIM not only promptly notified the data subject and the Authority but also took appropriate protective measures by adding the line to the exclusion lists and formally filing a complaint against the responsible partner.

- Case No. 500303: The matter did not involve the exercise of a right related to personal data protection, but rather the fulfillment of a contractual right (i.e., a request for erasure of an email account). Due to a technical issue related to a landline recently canceled by the User, which hindered the automatic deactivation of the email account, the Company took action through manual intervention by its technical staff. The matter was resolved to the data subject’s full satisfaction, and TIM provided timely formal and telephone responses throughout the year 2025.

- Case No. 520955: In this instance as well, the original request filed in July 2025 concerned solely a contractual right related to the reset of login credentials, to which the Company provided a correct and timely response. The subsequent privacy-related request regarding data storage periods (August 2025) was not resolved due to an isolated clerical error in the IT classification system, which triggered the automatic closure of the internal workflow; this constituted an exceptional anomaly and is not representative of standard company practice.

- File No. 514826: In response to the access request filed on July 17, 2025, regarding alleged promotional contacts and a request for information on the disclosure of data to third parties, TIM provided an initial interim response within the statutory timeframe and subsequently issued its final response on October 15, 2025. Internal investigations ruled out any violation or accountability on the part of the Company, as the calling numbers could not be traced back to TIM or to its network of authorized partners. 

3.5. Measures Adopted by TIM

With regard to the procedures for handling requests from data subjects to exercise their data subject rights, the Company highlighted the implementation of numerous organizational and procedural safeguards aimed at continuously strengthening its privacy governance. Among the measures already in place, TIM listed the adoption of automated classification systems for requests received via PEO and PEC channels, based on text recognition rules, the activation of automated supplementary notifications in the event of technical anomalies in attached files, as well as the extension of the timeline monitoring system (SLA Management) to nearly all requests to ensure end-to-end process control.

From a strictly operational and human resources management perspective, the Company acknowledged a significant strengthening of its internal organizational structure through the establishment of specific, distinct teams tasked, respectively, with reviewing traffic logs, handling privacy requests other than those related to traffic logs, and addressing reports submitted to the Data Protection Officer (DPO). The Company reported that it supplements these coordination mechanisms with regular, specialized training sessions for staff, supplemented by surveys and the sending of systematic reminders focused on the need to comply with the time limits for processing cases.

Finally, with regard to medium-term strategic planning, TIM’s representative stated that further corrective measures aimed at improving the timeliness and quality of the Company’s operations are currently under advanced evaluation. Specifically, the Company has formalized its commitment to optimizing messages that redirect users to dedicated thematic channels, extending automatic classification to additional corporate email inboxes, and, lastly, drastically simplifying the procedure for revoking consent for direct marketing purposes, to be achieved through the complete elimination of the previous IT authentication mechanisms.

3.6. Failure to Comply with Procedural Deadlines and Violation of the Ne Bis in Idem Principle

TIM argued that the Authority’s power to impose sanctions had lapsed due to the expiration of the 120-day deadline for serving the notice of charges, as provided for in Table B of Regulation 2/2019. According to the Company, this limitation period began on April 17, 2025, the date on which the collection of investigative evidence was completed following the conclusion of the inspection activities (formalized through the notice of resolution of the Reservations). Therefore, taking into account the summer suspension of deadlines (August 1–31) provided for in Art. 6, paragraph 1, of the aforementioned Regulation, the deadline for the valid service of the notice of objection would have inevitably expired on September 15, 2025.

For the purposes of calculating procedural deadlines, TIM also noted the clear inadequacy of the voluntary communications sent by the Company to produce any suspensive effect. According to TIM, the suspension mechanism provided for in Art. 7 of Regulation 2/2019 applies exclusively to the period of time between a formal request for information from the Authority and the party’s response thereto. It follows that the unsolicited submissions presented by TIM would not have interrupted or suspended the course of the proceedings. The Company also considers the subsequent requests for information made by the Authority in October 2025 to be irrelevant, as they occurred at a stage when the Authority’s power to impose sanctions had already expired.

In the Company’s view, even if one were to hypothetically grant suspensive effect to the aforementioned unsolicited submissions, the deadline would in any case have expired on January 20, 2026.

Finally, the Company considered the Authority’s practice of consolidating complaints during the hearing process to be unlawful: according to TIM, the regulations invoked for this purpose would have justified joint consideration only for the purpose of issuing general measures, thereby revealing their incompatibility with the adoption of specific sanctioning acts. In light of the foregoing, TIM requested the immediate dismissal of the proceedings.

In addition to the Authority’s loss of sanctioning authority, in its defense briefs, The Company also represented that the issues concerning the governance of telesales and telemarketing channels, as well as the system for monitoring the data chain from initial contact to contract completion, are currently sub judice. TIM has pointed out that these issues are, in fact, the subject of a court-appointed expert report (CTU) ordered by the judicial authority in the context of the proceedings (R.G. 23522/2023) initiated by the Company itself to challenge the previous Sanction Order No. 183/2023 issued by this Authority.

Regarding the court-appointed technical expert report, the Company emphasized that the questions posed by the judge largely mirror today’s allegations. Specifically, TIM noted that the court-appointed expert was tasked with assessing the adequacy of the Company’s past and current systems designed to ensure the traceability of transactions, the lawfulness of promotional contacts made using numbers registered with the ROC, and the proper handling of requests from data subjects. According to TIM, the expert investigation is specifically aimed at identifying any additional corrective measures the Company should have adopted to comply with current regulations.

Based on these preliminary findings, the Company argued that the imposition of an additional and independent sanction by this Authority would be irreconcilably at odds with the rules on lis pendens (resulting in the erasure of the lawsuit from the docket pursuant to Article 39 of the Code of Civil Procedure) or the rules on res judicata on the merits (pursuant to Article 2909 of the Civil Code). Citing Supreme Court case law, TIM argued that res judicata covers both the claims raised and those that could have been raised, precluding the repeated exercise of sanctioning power over the same subject matter of the dispute, in order to prevent the endless proliferation of lawsuits and the risk of conflicting rulings.

Finally, the defense argued that the two proceedings are substantively and legally identical, as they share the same triad of constituent elements. In particular, the Company asserted that the parties (the Authority and TIM), the substantive claim (the annulment of the order and the consequent validation of corporate governance), and the cause of action (the alleged inadequacy of corporate control systems over the data chain), and therefore contended that the Authority’s sanctioning action was precluded.

3.7. The Company’s Hearing

During the hearing, requested pursuant to Article 166, paragraph 6, of the Code and held on May 6, 2026 (minutes ref. no. 69385), the Company reiterated its arguments in full, focusing on the ongoing strengthening of its accountability system. TIM emphasized that the problematic phenomenon of so-called “unregulated telemarketing” is attributable exclusively to fraudulent conduct carried out by abusive third parties operating outside the Company’s organizational framework with specific intent. Citing the guidelines of the Court of Justice of the European Union, TIM invoked the principle of specific subjective accountability on the part of the direct offenders, characterizing the Company as the injured party burdened by onerous compliance costs and serious reputational damage.

With regard to the substantive findings, TIM denied that the personal data was originally unlawful, arguing that the “Lead” technique is systematically supported by the express consent of the data subject and noting that none of the thirty-six cases examined resulted in the formal establishment of a contractual relationship. The Company further argued that there are objective technical and regulatory limitations in combating the phenomenon of spoofing, specifying that the adoption of unilateral preventive blocking measures would pose a high risk of disruption to essential services; to this end, it emphasized the need for a systemic, erga omnes intervention under the direct supervision of the competent authorities.

With regard to technical and organizational risk mitigation measures, the Company outlined the substantial financial investments made to implement real-time IP address tracking and to strengthen opt-out mechanisms. Regarding oversight of the sales network, the Company noted that it had undertaken rigorous corrective actions during the first quarter of 2026, culminating in the termination of contractual relationships with non-compliant agencies, the introduction of binding onboarding procedures with preliminary “privacy maturity” assessments, and the establishment of contractual trial periods with the right to terminate at will. Finally, it acknowledged the provision of extensive training to customer care staff and the imminent release of technological implementations aimed at simplifying the withdrawal of marketing consent.

Based on these elements, the Company requested that the sanctioning proceedings be dismissed.

The Authority took note of the comprehensive defense represented and granted TIM a deadline to submit a detailed summary of supporting documents and an analytical breakdown of the financial investments made in the areas of technological and legal compliance. 

In a letter dated May 15, 2026, ref. no. 75146/26, TIM provided evidence of the substantial costs incurred and/or to be incurred for the implementation of the measures outlined by TIM during the hearing and for additional activities to combat unsolicited telemarketing.

4. THE AUTHORITY’S ASSESSMENTS

Having examined the case file, the findings of the preliminary investigation, and the defense brief filed, the Authority considers the complaints raised by TIM to be unfounded and, accordingly, confirms (with the exception of certain minor violations) the Data Controller’s accountability with respect to the charges brought, for the factual and legal reasons set forth below, which are to be considered in conjunction with the observations and findings already expressed in the aforementioned statement of charges.

4.1. On TIM’s Governance

With regard to TIM’s defense arguments concerning the fairness of its governance and the “non-reprehensibility” of any conduct on the part of the Company, the following observations are made.

First, TIM commits a logical and legal fallacy by assuming that the formal adoption of a governance model automatically precludes fault.

Compliance with the provisions of the Code is not, in and of itself, sufficient if the measures implemented prove ineffective in practice, or if the processing continues to violate the provisions of the Regulation. It is not enough to demonstrate that formal rules have been “prescribed” for entities in the supply chain; rather, it is necessary to prove that their actual application and substantive effectiveness have been verified.

TIM emphasizes its adherence to the Code of Conduct, noting that “while the Code of Conduct does not exhaust accountability, data controllers adhere to the Code of Conduct with an expectation of legal certainty and the appropriateness of the prescribed measures.”

Specifically, the Company noted that Codes of Conduct are “precisely accountability measures aimed at ensuring that data controllers strike a proper balance of interests, thereby relieving them, at least in part, of the need to prove their own accountability and the compliance of the measures adopted” (EDPB Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under the Regulation).

The Company errs in equating adherence to the Code with a “free pass” that would guarantee it immunity from sanctions. Such an automatic assumption runs counter to both the core principles of the Regulation and the very wording of EDPB Guidelines 1/2019, which TIM itself cites.

EDPB Guidelines 1/2019 expressly clarify that “Adherence to a code does not in itself guarantee compliance with the Regulation nor immunity for the controller or processor from sanctions or accountability under the Regulation.”

Adherence may certainly be taken into account by the Authority in determining the severity of the sanction (as a mitigating factor, pursuant to Article 83(2)(j) of the Regulation), but it does not eliminate the violation committed nor preclude corrective action. As clarified in the Guidelines: “in the event of a violation of any provision of the Regulation, adherence to an approved code of conduct may indicate a greater or lesser need to impose an effective, proportionate, and dissuasive administrative fine or to resort to another corrective measure by the supervisory authority.”

Second, TIM’s argument that, pursuant to Article 28(10) of the Regulation and the case law of the CJEU, accountability for unlawful processing would rest exclusively with the so-called “underground” entities —a phenomenon that is allegedly beyond the controller’s control—cannot be accepted.

The Authority has outlined principles that impose specific obligations on the controller to supervise and monitor the activities of processors. Failure to implement such safeguards constitutes, for all intents and purposes, negligence on the part of the data controller (see, inter alia, Decision No. 352 of May 14, 2026 (web doc. No. 10262507); Decision No. 228 of April 10, 2025 (web doc. No. 10127930); Decision No. 205 of April 11, 2024 (web doc. No. 10008076)). Specifically, the Authority clarified that a controller may be considered “at fault” for a violation committed by the processor if the controller has failed to exercise due oversight or has not adopted the necessary supervisory measures to prevent unlawful processing. In essence: if the data controller fails to actively supervise, this “failure to supervise” constitutes the fault justifying the sanction. Similarly, the controller’s accountability for processing carried out by its employees or agents (including call centers) may arise when there is an organizational deficiency or a lack of supervision. Although the client is not absolutely liable for the unlawful acts of others, it is liable for its own “negligence in supervision” or “negligence in selection.”

It is undisputed that:

- unidentified third parties made unlawful calls (using numbers not registered with the ROC and directed at numbers registered with the RPO) in the interest of and on behalf of the Company, and the streams of unlawfully acquired contacts by these “unauthorized” parties were fed into the company’s systems via activation orders for the benefit of TIM itself;

- the selection of processors took place in the absence of qualification and selection criteria for the agencies. Suffice it to note, by way of example, that TIM failed to verify whether the size of the partners’ workforce was commensurate with the volume of contacts generated;

- The monitoring system relies on information entered directly by the data processors themselves into the company’s systems;

- The system failed to detect glaring inconsistencies.

It should be added that the phenomenon of “underground” practices in telemarketing is not an unforeseeable event or a force majeure; it is a systemic and structural risk of the sector, widely known. The principal (TIM), which outsources promotional campaigns, has a duty to secure the supply chain by prohibiting unauthorized subcontracting (Art. 28, para. 2) and, above all, to establish traceability systems capable of detecting anomalies.

TIM cannot simply invoke the “adaptive spirit” of the “underworld” to claim victimhood. The fact that the company secures contracts and derives direct economic benefit from marketing campaigns without being able to guarantee the lawfulness of the supply chain that generated those leads makes it liable for its own failure to exercise due diligence.

Indeed, it is precisely the systemic and adaptive nature of the phenomenon—that is, its ability to change form to evade the controls put in place over time—that imposes on the data controller—who directly benefits from the proceeds of such promotional activities—a duty of supervision that is not static but proportionate to the evolution of the risk. This obligation must extend—including through appropriate on-site inspections—to the systematic analysis of inconsistencies discernible from the aggregated data as a whole, including, for example, the conversion rate of leads into actually concluded contracts and the incidence of customer complaints attributable to a specific agency. Only monitoring structured in this way—and not an isolated check of a single parameter—is capable of promptly detecting anomalies, as demonstrated, in the present case, by the discrepancies already highlighted in the narrative between reported leads and actual contacts made.

The Company also argues that it has “no visibility or control” over the phase “prior to the upload of the lead” and that it cannot “become aware of cases …in which the entry of data on the web form is prompted by prior unauthorized phone calls,” except through “complaints and reports received from data subjects and the authority.”

This argument cannot be accepted.

The Code of Conduct itself—which TIM states it has adopted as a model—does not permit any form of voluntary “blindness.” On the contrary, the Code imposes rigorous standards, requiring the client to verify the lawfulness of all steps leading to the generation of the contact, without limiting itself to the final stage of the process. It is expressly stated that: “Those adhering to this Code of Conduct ensure that the entire supply chain processes data exclusively on the basis of appropriate consent... [...].” “The controller guarantees, including through the necessary cooperation of its processors, full, timely, and constant oversight of the entire supply chain of entities involved in any preparatory or execution phase of the promotional campaign.”

With specific reference to the oversight of suppliers, it is stipulated that “Each adherent shall verify compliance with the requirements declared by the service provider through document review and/or internal inspection, at an appropriate frequency and using methods and tools suited to the actual circumstances...”.

Therefore, the fact that the leads arrived “clean” via a final web form does not justify the lack of oversight over the predatory techniques employed by the Company’s business partners (or downstream subcontractors) to drive Users toward those forms.

The controller, as the client benefiting from the generation of those commercial leads, has a duty of proactive oversight.

Placing “trust” in the Code of Conduct without actually applying its basic principle—namely, “full control of the supply chain and the preparatory phase”—amounts to evading accountability obligations.

Therefore, the sanctions imposed by the Authority are not only legitimate but also fully in line with current European (EDPB) and sector-specific legal principles.

4.2. On the inadequacy of the technical and organizational measures adopted by the Company in managing its contact databases (so-called “Leads”)

The objection that the corrective measure is allegedly “premature,” based on the recent implementation of the opt-out mechanism and the alleged absence of direct complaints, is without merit. Through the concept of Data Protection by Design, European legislation imposes on the controller an obligation of proactive—rather than merely reactive—prevention. The temporary absence of formal complaints during the first thirty days of the measure’s trial period does not remedy a system architecture that is, from the outset, manifestly unsuitable for ensuring the accuracy of the data and the data subject’s actual intent. Compliance with the Regulation is assessed based on the intrinsic adequacy of the measure and not on the mere absence of complaints from users. 

With regard to the “opt-out” system introduced by the Company during the investigation, it should be noted that sending an SMS containing a “cooling-off” or opt-out notice—within the strict 5-minute time limit—to auser added to the system by unidentified third parties overturns the legal model of consent, which requires (Art 4(11) of the Regulation and Recital 32) an unequivocal affirmative act by the data subject, and not merely their inaction within a predefined time limit. The data subject’s silence, far from being equated with consent, is identified here as the very prerequisite for the lawfulness of the processing, in direct contrast to what is expressly excluded by Recital 32 of the Regulation, according to which “silence, inactivity, or the preselection of checkboxes should not constitute consent.” The data subject, completely unaware that their data has been provided via the Lead form, is in fact forced to take action to prevent processing that they neither requested nor authorized, rather than the processing itself requiring, as a precautionary measure, an expression of their will. Furthermore, the chosen technical solution—namely, opening a link received via SMS—is itself at odds with the most basic precautions regarding cybersecurity and phishing prevention, and is therefore doubly unsuitable: in terms of the lawfulness and transparency of the processing, and in terms of the security of the means used to exercise the data subject rights.

TIM’s argument regarding the tracking of IP addresses as a measure allegedly suitable for mitigating the risk of fraudulent submissions is also irrelevant. The IP address log merely certifies the point of origin of the electronic connection but offers no evidentiary guarantee that the person filling out the form is the actual holder of the telephone number provided. Regarding the inability of these measures to curb the so-called “underworld” of illegal telemarketing, it is reiterated that the continued existence of widespread illegal activity cannot in any way exempt the data controller from adopting adequate security measures within the scope of its responsibility.

Furthermore, the argument that full and informed consent, obtained at the time the contract is finalized, would have a remedial effect with respect to any defect in the original acquisition of the lead cannot be accepted. The processing of personal data begins at the very moment of its collection; both the collection and the initial follow-up contact for a commercial purpose (so-called “outbound calls”) are, therefore, “operations” or “set of operations” that constitute “processing” and that, by their very nature, require—in relation to the specific purpose (in this case, commercial promotion)—a valid, sound, and verifiable legal basis. An unsolicited telephone contact made as a result of a “fake” or unverified lead already constitutes, in and of itself, a relevant processing of personal data pursuant to Article 130 of the Code and, as such, must be based on an adequate legal basis. Therefore, such processing cannot be subject to any retroactive regularization or validation.

To hold otherwise would lead to a result that distorts and runs counter to the rationale of the Regulation: admitting that subsequent consent, however genuine, could “clean up” an originally unlawful processing would amount to indirectly legitimizing the entire predatory technique of the fictitious lead, provided that the commercial operator ultimately succeeds in getting the data subject to sign up. In other words, the unlawfulness of the initial data collection occurs instantly and definitively at the time of processing, regardless of the outcome subsequently achieved; it is not subject to the parties’ control nor susceptible to retroactive regularization due to subsequent events, under penalty of substantially undermining the principle of lawfulness set forth in Art 6 of the Regulation and transforming it into a requirement that can be waived retroactively by the data controller who benefits from the violation.

Moreover, the very Code of Conduct invoked by TIM—which is intended to discourage clients from accepting contracts resulting from unlawful telemarketing activities—expressly provides that “if, following inspections, contracts are found to have been entered into as a result of an invalid initial contact, such contracts may continue to be performed provided that the client informs the data subject of the invalid origin of the contract and that the data subject confirms their intention to maintain it - the validity of contracts, with the possibility of canceling contracts concluded by telephone in the event of an unlawful initial contact” (see Art. 16, paragraph 6, of the Code of Conduct).

The argument based on the absence of an opt-in system in current “market practices” and the resulting risk of a competitive disadvantage is also without merit. The accountability requirement (Art 5, para 2, of the Regulation) requires the data controller to comply with the law regardless of the commercial practices adopted by competitors, especially where such practices result in a restriction of the rights of data subjects. There can be no exemption based on widespread violations of the law by third parties. On the contrary, it is precisely the accountability referred to in para 2 of Article 5 of the Regulation (which entails the general accountability of the controller under Article 24 of the Regulation and the aforementioned principles set forth in Article 25) requires that the principles governing the proper processing of personal data set forth in para 1 of the same article be applied, taking into account the context, nature, and potential risks of the specific processing carried out. Whether a particular measure is mandatory or not therefore depends not on market practices but on an examination of the specific processing being carried out.

Moreover, this Authority has already ruled against opt-out mechanisms structurally similar to the one adopted by TIM. In Decision No. 574 of May 9, 2024 (web doc. No. 10107938), the Authority criticized an SMS opt-out system with a time window of only a few minutes, deeming it unsuitable for discouraging the mass addition of phone numbers via bots and for protecting data subjects unaware that they had been subscribed, while reaffirming the preference for the double opt-in model. Similarly, in Decision No. 401 of June 20, 2024 (web doc. No. 10040382), the Authority ruled that a promotional communications system based on opt-out rather than opt-in was unlawful, and in Decision No. 330 of June 4, 2025 (web doc. No. 10143278), it censured the adoption, by third-party providers tasked with lead generation, of consent tracking systems lacking the necessary guarantees of verifiability. These precedents confirm that the Authority’s position on this matter does not constitute an ad hoc imposition in the present case, but rather the application of a well-established and publicly disclosed principle, of which the Company, as an industry operator subject to specific oversight, could not have been unaware.

With regard to the invoked principle of good faith cooperation, while acknowledging the Company’s stated efforts to comply, the Authority cannot refrain from imposing mandatory measures where the proposed ones are structurally deficient.

In light of the above considerations, it is reiterated that the adoption of a rigorous opt-in-based prior verification procedure (such as, for example, sending a One-Time Password —OTP—to validate the number) represents, as the technology currently stands, one of the technical and organizational measures that have proven to be effective and suitable for preventing the use of fictitious personal data and ensuring that the processing fully complies with the principles set forth in Article 25 of the Regulation.
Only by making the inclusion of phone numbers in contact databases contingent upon a positive, unequivocal, and pre-verified action by the actual owner of the telephone line can the necessary balance be achieved between the Company’s legitimate commercial expectations and the protection of the fundamental rights and freedoms of the data subjects.

4.3. On the systemic nature of the violations and the invalidity of consent (so-called “fictitious leads”). Groundlessness of the defense arguments regarding individual investigative files.

An examination of TIM’s defense brief and the investigative documentation reveals a pattern of widespread and systematic data breaches, attributable to a structural inadequacy in the Company’s organizational structure and the control mechanisms it has implemented to oversee the operations of its sales network (agencies and business partners).

The defense’s argument that the Company acted correctly by merely managing leads (requests for follow-up contact) that, within the system, appeared formally valid—since the data controller could not have been aware of the prior unlawful “nuisance” calls—cannot be accepted.

As already noted, in fact, this argument stands in clear contrast to the core principles of the Regulation, and in particular to the frequently cited principle of accountability (Art. 5, para. 2, and Art. 24). The controller cannot, under any circumstances, hide behind the apparent formal correctness of the data entered into the system when the entire data collection architecture proves incapable of detecting and blocking anomalous data flows.

As amply demonstrated during the inspection, the leads in question cannot under any circumstances be considered validly provided. In fact, it has been proven that the “click” made by the user on the link received via SMS or messaging was in no way the result of an independent, spontaneous, and informed request by a data subject interested in TIM’s services. On the contrary, this action was artificially induced by the telecommunications operator during an initial abusive contact, carried out without consent, often through spoofing techniques or targeting subscribers enrolled in the RPO. 

It follows that the initial contact is fundamentally unlawful under Articles 6 and 7 of the Regulation and Article 130 of the Code, thereby irreparably invalidating the entire processing chain. The alleged “consent” obtained following deceptive and disruptive conduct—and, in any case, after processing had already begun—is neither freely given nor specific, but constitutes a mere technical expedient devised to fictitiously “clean up” the unlawful origin of the data in the controller’s databases. TIM, as the data controller, is liable for the conduct of the parties it engages (Art. 28 of the Regulation), as it is subject to serious negligence in both the selection and supervision of such parties.

Equally irrelevant is the fact that none of the cases in question resulted in the formal establishment of a contractual relationship with the Company, given that (i) this outcome did not stem from a direct initiative or careful monitoring attributable to the Company, but rather from the User’s own decision, who—after conducting an independent verification and realizing the fraudulent conduct—refused to confirm or requested the cancellation of the order; (ii) the mere activation order constitutes, in and of itself, sufficient evidence to prove the unlawful acquisition of Users’ personal data, carried out on behalf of TIM and fed into the company’s IT systems.

The inadequacy of TIM’s control systems is confirmed by an examination of the individual complaints and reports, with respect to which the Company’s justifications must be rejected for the following reasons.

- Cases Nos. 425095, 496215, and 437668: The Company argues that the calling numbers are unrelated to its own network; that the leads generated by XX and XX appear to be legitimate; and that no contract was concluded. This defense is without merit. The very fact that the Company’s systems accepted as “formally correct” leads resulting from persistent abusive calls demonstrates a violation of Art. 25 of the Regulation (Data Protection by Design and by Default). TIM’s IT systems were designed without taking into account the upstream phase of data processing, thereby allowing partners to enter flawed data. The subsequent termination of relations with the agencies constitutes an acceptable but belated remedy, which does not remedy the original unlawful data processing nor the failure to exercise preventive oversight.

- Cases Nos. 434470 and 444902: In these instances as well, the Company argues that the leads generated by XX and XX appear to be legitimate. In this regard, reference is made to the arguments already presented in the previous point concerning the structural inadequacy of TIM’s organizational structure. In the case referred to in File No. 444902, a particularly serious issue emerges: the partner XX, already rated as “INADEQUATE” by TIM in November 2023 due to extremely serious violations, continued to enter unlawful contracts into the system. The fact that the agency was kept operational through mere “documentary monitoring” constitutes a gross violation of Articles 28 and 32 of the Regulation.

- Files Nos. 513320 and 518841: The records show that partner XX uploaded activation orders to TIM’s corporate systems following multiple unlawful contacts. The fact that the contracts were not finalized or that the User exercised the right of withdrawal pursuant to Art. 16 of the Code of Conduct does not negate the occurrence of the violation. The right of withdrawal pertains to the contractual sphere, not to the lawfulness of data processing, which remains fundamentally flawed due to the lack of an appropriate legal basis.

- Case No. 557370: The Company’s defense, which seeks to characterize the offer of the “TIM Vision” service as a complimentary gift as a service communication based on Art 6(1)(b) of the Regulation (performance of a contract), cannot be accepted. While acknowledging that the communication in question is intended to inform the customer of the possibility of taking advantage of a benefit linked to the existing contractual relationship, it should be noted that the aforementioned provision of the Regulation makes the lawfulness of the processing contingent upon the strict requirement that it be “necessary” for the performance of the contract. In the present case, it is clear that free subscription to “TIM Vision” is in no way necessary for the performance of the complainant’s telecommunications contract. The offer of this additional product pursues a clear commercial purpose within the meaning of Article 130, paragraphs 1 and 2, of the Code. In fact, this category includes any initiative—even one that is not strictly advertising—aimed at promoting one’s own products or services and building customer loyalty as part of a broader marketing strategy. Therefore, such a communication required the prior and specific consent of the data subject pursuant to Article 130 of the Code. Since the User denied such consent, the communication is unlawful.

TIM’s objection regarding the “initial defense” nature of the brief filed for certain cases is also irrelevant, given that it serves as an appropriate means of ensuring the effectiveness of the adversarial principle.

The data controller’s accountability is definitively confirmed by the glaring statistical discrepancies regarding monthly activation volumes (e.g., November 2024), as previously mentioned.

Cross-referencing the log files revealed extremely significant anomalies: Agency XX, despite reporting approximately 6,000 leads, made over 16,000 contacts; Agency XX generated over 22,000 contacts with an activation rate of less than 4%.

These mathematical findings are sufficient to fundamentally undermine the presumption of the data controller’s good faith. From a logical and legal perspective, the generation of a genuine lead—which, by definition, should presuppose a targeted and informed request from the User—is incompatible with such a large volume of unsuccessful or rejected contact attempts. Faced with statistically anomalous conversion rates and volume discrepancies of this magnitude, the Company, in accordance with the principles of accountability and security (Articles 5, 24, and 32 of the Regulation)—should have initiated verification measures, upon the outcome of which the immediate blocking of traffic flows and the activation of automated alerts could have been implemented. The fact that it passively accepted such volumes of traffic demonstrates a complete lack of substantive audits regarding the appropriateness and operational methods of the agencies designated as processors, effectively endorsing the use of “phantom” call centers.

While this Authority views positively the Company’s stated intent to strengthen its monitoring controls through the introduction of specific anomaly indicators (so-called “triggers”) designed to initiate second-level verifications, cannot, however, refrain from censuring the conduct exhibited to date and the related violations ascertained with regard to past processing activities.

In light of the foregoing considerations, it must be deemed proven that the data controller has structured and maintained an organizational and IT system that is unsuitable for ensuring the lawfulness of the processing operations carried out by its sales chain.

TIM is therefore found to have violated the following regulatory provisions:

- Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having allowed the carrying out of abusive promotional contacts—disguised as false requests for a callback—in the absence of prior, free, and specific consent;

- Article 5, para 2, of the Regulation: for violating the principle of accountability, by failing to adopt control systems capable of ensuring and demonstrating effective oversight of the lawfulness of its sales network’s operations;

- Articles 24, 25, and 28 of the Regulation: for failing to adopt appropriate technical and organizational measures from the design phase of the processing (data protection by design), suitable for preventing the upload of contracts originating from unregistered or disguised phone numbers and for ensuring compliance with the mandatory instructions provided to partners;

- Article 32 of the Regulation: for the insufficiency and inadequacy of security measures relating to consent collection processes and order-upload systems.

4.4. On the Inadequacy of Opt-Out Procedures and Obstacles to the Exercise of Rights

Having examined the defense brief submitted by TIM, this Authority finds that the arguments set forth therein are insufficient to rebut the findings set forth in the notice of violation, thereby confirming the existence of systemic and organizational shortcomings in the handling of data subjects’ requests (except for the specific case referred to in file no. 519239).

With regard to the reports concerning TIM’s failure to process requests by data subjects to exercise their data subject rights, the following observations are made. Regarding:

- File No. 478291: The justification provided by the Company regarding the “technical timeframes” required to align the information systems is insufficient to justify the continued sending of the contested promotional communications. The fact that such communications continued for more than four months after the objection was filed highlights a clear inadequacy of the technical and organizational measures adopted by the controller. A mere formal response within 30 days is ineffective unless accompanied by a timely and substantive cessation of the processing.

- Case Nos. 438663 and 517806: The data subjects’ use of corporate communication channels that are allegedly “inappropriate” (certified email [PEC] for unsolicited telemarketing or an email address belonging to a Data Protection Officer [DPO] who is in the process of leaving the company) and any “technical anomalies” do not invalidate the request. It is the data controller’s responsibility, in accordance with the principle of accountability, to establish internal document workflows capable of correctly intercepting and routing privacy requests received at its official contact addresses. 

TIM is therefore found to have violated the following provisions:

- Articles 17 (Right to erasure) and 21 (Right to object) of the Regulation, for failing to act on the requests of the data subjects;

- Articles 6, para 1, subparagraph (a) of the Regulation and Article 130, paragraph 2, of the Code, in that the sending of additional promotional communications, following an objection or a request for erasure, took place without valid consent and, therefore, lacked a proper legal basis.

With regard to the complaints referred to in case files nos. 438663, 517806, 443623, 448740, and 557370 concerning the implementation of cumbersome opt-out procedures—which make the revocation of consent contingent upon access to the MyTIM (MyTIM) or the use of specific applications, it is noted that this mechanism is in clear contrast to the principle enshrined in Art 7, para 3, of the Regulation, according to which the withdrawal of consent must be as easy as giving it. The Company’s reference to Article 12(6) of the GDPR (the need to verify the applicant’s identity) appears irrelevant and self-serving. Digital authentication cannot result in a disproportionate burden that effectively precludes or discourages the exercise of this right, in clear violation of Art. 12(2) of the Regulation.

With specific reference to cases nos. 443623 and 448740, the fact that one of the data subjects (case no. 448740) was a TIM customer and that both data subjects ultimately acted independently or contacted this Authority directly does not retroactively remedy the original shortcomings of the opt-out system, which imposed undue obstacles that required external intervention or extended timeframes to be resolved.

Only in one case, file no. 519239, does the Authority agree with the argument and legal framework presented by TIM. An examination of the documentation on file revealed that, in this specific case, TIM’s sending of promotional emails was based on valid, prior consent expressly given by the data subject upon signing a “business” contract. The failure to complete the unsubscribe procedure, on the other hand, is attributable to a clerical error on the part of the complainant. The case in question is therefore deemed closed.

In light of the foregoing, TIM is found to have violated the following provisions:

- Article 12, para 2, of the Regulation, for failing to facilitate the exercise of data subject rights;

- Articles 15 through 22 of the Regulation, for violating the applicable provisions regarding the exercise of rights, thereby rendering the request for objection or erasure ineffective;

- Art 24 of the Regulation, for failing to implement adequate technical and organizational measures to promptly and effectively accommodate the wishes of data subjects.

4.5. Regarding the failure to respond, or the late or inadequate response, to requests from data subjects

The defense arguments regarding the residual and purely statistical nature of the delays, although supported by quantitative data from 2025, do not negate the unlawfulness of the individual violations alleged. The Regulation is designed to protect the fundamental rights and freedoms of individuals; therefore, the statistical efficiency of the system does not constitute a defense for violations committed to the detriment of individual complainants. This circumstance, if duly proven, may nevertheless be taken into consideration—not for the purpose of establishing the violations, but rather when determining the penalty—as an indicator of the overall adequacy of the organizational structure established by the Data Controller pursuant to Article 83, para 2, of the Regulation.

Furthermore, there has been a distorted and non-compliant use of so-called “interim responses.” Article 12, para 3, of the Regulation permits an extension of the original 30-day deadline by up to two additional months only in cases of proven complexity, but requires the Data Controller to inform the data subject of such an extension and the reasons for it within one month of receiving the request.

- File No. 514826: A response time of 88 days cannot be justified by the mere transmission of an interim response if it does not meet the formal and substantive requirements for an extension set forth in Art. 12, para. 3. The need for cross-checking does not justify exceeding the mandatory maximum time limits.

- Files Nos. 425095 and 513320: The accumulated delays of 120 and 51 days, respectively, demonstrate the ineffectiveness of the response procedures. It should also be noted that, with regard to File No. 425095, contrary to the Company’s claims, the “final confirmation” was not received on February 24, 2025, at all. In that vague and evasive communication, TIM merely confirmed that the order had been entered into TIM’s systems by a “sales network agency” without, however, disclosing its name and citing, in this regard, the “particular complexity of such operations.” It was not until March 26, 2025—120 days after the initial request and only after the Authority had launched its investigation—that the Company complied with the complainant’s request by informing her that the data had been processed by Agency XX. The 120-day delay exceeds even the maximum and absolute three-month deadline (30 days plus a two-month extension) granted by European legislation for cases of extreme complexity. The fact that the contacts originated from third parties or business partners reinforces TIM’s accountability for selecting and supervising the operations of its sales chain, as the Data Controller cannot shift the blame for the inefficiencies of its organizational and control structures onto the data subject.

- Cases Nos. 500303 and 520955: The distinction made by TIM between “contractual prerogative” and “right to privacy” is deemed valid. A request for erasure of an account and a request to reset one’s email password do not fully fall within the scope of exercising a privacy right. Case No. 500303 is therefore removed from the filing system. However, with specific reference to case no. 520955, the clerical error in the IT classification system that resulted in the failure to respond to the complainant’s subsequent request regarding storage periods constitutes evidence of an organizational deficiency attributable to the Data Controller.

Consequently, TIM is found to have violated Articles 5(1)(a) and (2), as well as Articles 12, 15, 17, and 21 of the Regulation.

4.6. On the Procedural Objections Raised by the Company

Finally, the objections raised by the Company regarding the conduct of the preliminary investigation and, more generally, the proceedings at hand cannot be upheld.

4.6.1. Alleged Lapse of the Authority’s Power to Impose Sanctions

The arguments put forward by the Company regarding the alleged lapse of this Authority’s power to impose sanctions due to the expiration of the 120-day deadline for serving the notice of initiation of proceedings (pursuant to Article 166, paragraph 5, of the Code and Table B, point 2, of Regulation No. 2/2019, hereinafter also referred to as the “notice of charges”), are manifestly unfounded.

As a preliminary matter, it should be noted that the assertion that the 120-day period provided for in Regulation No. 2/2019 began to run on April 17, 2025 (i.e., the date of the so-called “Notice of Withdrawal of Reservations”).

The record shows that the preliminary investigation had by no means been concluded in April 2025: TIM itself subsequently submitted three Media Updates to this Authority (on July 4, July 31, and December 9, 2025, respectively), providing additional information on the systems and measures adopted by TIM that were the subject of the investigation. Furthermore, from April through December 2025, the Authority continued to receive hundreds of complaints against TIM regarding cases similar to those under investigation; in light of this, in October 2025, the Authority decided to issue additional requests for information regarding certain cases (see case files nos. 496215, 478291, 500303, 513320, and 514826).

Therefore, the Company’s argument—aimed at denying any procedural relevance to these submissions on the grounds that they were “spontaneous” and unsolicited, in order to invoke the expiration of the deadlines on September 15, 2025—appears specious and logically paradoxical. The party’s attempt to introduce new elements into the investigative file (which it expressly describes as “media updates” to the inspection reservations), implicitly asking the Authority to evaluate them, only to then argue that the Authority must disregard them for the purposes of calculating procedural deadlines.

Since the investigation continued, the elements relevant to establishing the violation could not have been finalized prior to the receipt of the last relevant note submitted by TIM on December 9, 2025 (registered under No. 174524 on December 16, 2025).

Even if one were to disregard the established case law of the Court of Cassation—which identifies the moment of determination not as the time of the actual receipt of the investigative documents, but rather as the time of their comprehensive evaluation—and were to assume (purely hypothetically) that the date of TIM’s last note coincides with thethe actual “determination of the violation” pursuant to Regulation No. 2/2019—and thus recital December 9, 2025, as the starting point for the calculation—the 120-day period would have expired on April 8, 2026.

Given that the notice of initiation of proceedings pursuant to Article 166, paragraph 5, of the Code was duly served on the Company on February 9, 2026 (i.e., two months prior to the deadline), it follows that the administrative action was fully timely and in strict compliance with the time limits imposed by applicable law. 

In light of this chronological reconstruction, the Company’s invocation of the suspension mechanism provided for in Art. 7 of Regulation No. 2/2019 appears to be irrelevant. The provision in question, in fact, governs the suspension of a time limit that has already begun to run, making it contingent upon a specific prerequisite that differs from the one at issue: a formal request by the Authority to the applicant to provide “information, additional details, or clarifications” or to submit documents, with the resulting resumption of the calculation “from the expiration date of the deadline set for the requested compliance.” The reasoning set forth above, however, does not require the application of any suspensive provision, since it does not concern the suspension of a time limit already in progress, but rather the identification of the starting date from which the time limit itself begins to run. Since this deadline is extended based on the progressive consolidation of the investigative documents, it has in any case been amply respected; the reference to Article 7 therefore falls on a different logical-legal plane and is irrelevant to the matter in dispute.

It is also decisive to note that TIM’s three Media Updates were all received before the expiration of the 120-day period and the alleged exhaustion of the authority to impose sanctions (the first, dated July 4, for example, was received just 78 days after April 17).

Finally, the objection regarding the alleged illegality of the joint handling (aggregation) of multiple complaints or reports in the context of sanction proceedings is rejected. The consolidation of proceedings concerning similar cases or the same processing activities carried out by the same data controller is not only provided for in Art. 10, paragraph 4, of Regulation 1/2019, but also meets the criteria of sound administration, effectiveness, and cost-efficiency of administrative action enshrined in Law 241/1990, ensuring a comprehensive and consistent assessment of the alleged violations, while fully upholding the principle of proportionality in any determination of the amount of the penalty. This approach, moreover, serves as a safeguard for the controller itself: combining the cases into a single proceeding allows for the possible application of the absorption mechanism provided for in Art. 83(3) of the Regulation, whereby, in the event of a violation of multiple provisions relating to the same processing or related processing operations, the total amount of the fine may not exceed that provided for the most serious violation. Had the same conduct been pursued separately, through the initiation of multiple independent penalty proceedings, the data controller would have been exposed to the risk of a far more severe overall outcome, as well as to a multiplication of the procedural and defense costs associated with managing multiple parallel investigations.

In light of the above considerations, the objections raised by TIM must be rejected in their entirety, and the full legitimacy of the Authority’s actions must be confirmed.

4.6.2. Alleged Violation of the Ne Bis in Idem Principle

With regard to the objections raised by the Company concerning alleged lis pendens and the violation of the ne bis in idem principle, the Authority considers the arguments to be entirely unfounded for the reasons outlined below.

The administrative proceeding concluded with Decision No. 183/2023—currently sub judice and in connection with which the court has ordered a court-appointed expert opinion (CTU)—is fundamentally distinct from the present investigation, as there is no identity between the parties, the subject matter sought, and the cause of action: the case files under review, the data subjects involved, the specific situations analyzed, and the contested processing operations are, in fact, different.

The previous decision concerned the use of contact lists for promotional purposes and outbound calls by partners, a practice that has now been almost entirely abandoned; the current proceeding, on the other hand, focuses on new methods of customer acquisition, based on requests for follow-up contact (leads) made by Users after viewing offers on digital channels (websites, social media, or comparison sites).

The fact that a court-appointed expert assessment on corporate governance is pending does not, therefore, grant the Company an “absolute license of lawfulness” for the entirety of the processing activities carried out, nor does this circumstance exempt the Authority from its duty to open new proceedings and initiate new investigations in response to new facts that may constitute separate violations of data protection regulations.

Even where a formal overlap is found between the contested regulatory provisions, there is no substantive overlap, as demonstrated by the application of the principle of accountability (Art. 5(2) of the Regulation) in the two proceedings: in Decision No. 183/2023, the violation of Article 5(2) was established in close connection with the lawfulness of the original data collection and the initial contact with the potential customer, whereas in today’s decision, the violation concerns not only the lawfulness of the data, but also structural organizational deficiencies, critical issues in the security of processing, and specific omissions in the design of the system of controls over the data chain.

The principle enshrined in Art 5(2) of the Regulation is, moreover, of general application and allows the Authority to impose accountability measures for omissions on the part of the data controller relating to factual and legal situations that are profoundly different from one another: the processing of personal data, in fact, consists of a multitude of operations and involves numerous actors and therefore cannot be assessed as a single block that is either unambiguously lawful or unlawful.

The Authority has full discretion to focus its actions on specific segments and procedures, particularly when dealing with complex organizational structures: addressing the same data controller on multiple occasions does not constitute a violation of the ne bis in idem principle, but rather a scenario expressly provided for by the Regulation, whose Art. 83(2), para. subparagraphs (e) and (i), requires the Authority to take into account “any relevant previous infringements” and compliance with prior measures adopted “in relation to the same subject matter.”

Therefore, the adoption of corrective and sanctioning measures in quick succession against the same company, while examining distinct aspects and processing operations, falls within the full and legitimate exercise of the Authority’s institutional duties.

5. CONCLUSIONS

In light of these considerations, the issues raised in the notice initiating the proceedings pursuant to Article 166 of the Code are confirmed, as the statements made during the investigation and the defenses raised are insufficient to rebut the findings made by the Office.

Therefore, the Authority finds TIM S.p.A. accountable for the following violations:

a. Articles 24, 25, and 28 of the Regulation, for having implemented technical and organizational measures that were inadequate to ensure, from the design stage, that processing is carried out, in every respect and at any stage and/or level, in accordance with the Regulation, including with regard to processing carried out by data processors;

b. Articles 5(1), 6, and 7 of the Regulation and Article 130 of the Code, for having contacted or allowed third parties to contact Users registered in the Do Not Call Registry without a valid legal basis;

c. Art 5(2) of the Regulation, the principle of accountability, for failing to adopt and/or demonstrate that it had adopted adequate control and oversight systems for the sales network;

d. Art 32 of the Regulation, for insufficient security measures regarding the collection of consents and the order-processing systems;

e. Articles 12(2) and (3) of the Regulation, for failing to facilitate the exercise of rights, for failing to respond to requests to exercise rights, or for responding with unjustified delay;

f. Articles 15 through 22 of the Regulation, for violating the applicable provisions regarding the exercise of data subjects’ rights.

The Authority orders the dismissal of cases nos. 519239 and 500303 for the reasons set forth in the grounds.

Having also established the unlawfulness of the Company’s conduct with respect to the processing operations under review, it is necessary to:

- to order TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to implement corrective measures in the customer follow-up procedure following requests submitted through the Company’s or its partners’ websites, in order to prevent the mass collection of phone numbers to be contacted and to ensure that consent to be contacted has been provided by the actual data subject;

- to order TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adopt adequate measures to monitor and supervise the activities of its partners and to ensure that promotional activities carried out on behalf of the Company are conducted in full compliance with personal data protection regulations;

- order TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adapt the procedures designed to ensure the exercise of the rights under Articles 15–22 of the Regulation, in order to prevent or at least significantly reduce instances of failure to respond, delayed responses, and systematic extensions of deadlines;

- issue an injunction, pursuant to Article 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981, to impose on TIM S.p.A. the administrative fine provided for in Art. 83, paragraphs 3 and 5, of the Regulation.

6. INJUNCTION ORDER

The violations indicated above require the adoption of an injunction order pursuant to Article 166, paragraph 7, of the Code and Article 18 of Law No. 689/1981 against TIM S.p.A.; since, in the present case, a violation of Articles 5, 6, 7, 12, 15 through 22, 24, 25, and 28 and 32 of the Regulation, as well as Article 130 of the Code, have been established, the provision set forth in Article 83, paragraphs 3 and 5, of the Regulation applies. 

With regard to determining the maximum statutory amount of the fine, TIM’s argument that only “revenue related to contracts concluded through leads generated by digital agencies” should be considered cannot be accepted: the Regulation itself expressly stipulates that the “total annual worldwide turnover for the preceding fiscal year” must be used as the reference (Art. 83(5) of the Regulation). In this regard, see also Recital 150 of the Regulation on the concept of an enterprise, according to which “where administrative fines are imposed on enterprises, enterprises should be understood as defined in Articles 101 and 102 TFEU for these purposes.” Therefore, based on current legislation and in accordance with previous decisions adopted by the Authority, reference must be made to the TIM Group’s revenue, as derived from the most recent available financial statements (December 31, 2025). It follows that, in the case at hand, the maximum statutory fine is determined pursuant to Article 83, paragraphs 3 and 5, of the Regulation at 549,360,000.00 euros.

In determining the amount of the fine, the factors set forth in Article 83, para 2, of the Regulation must be taken into account.

In the case at hand, the following factors are relevant:

- as a mitigating factor, the moderate severity of the violations (Article 83, para 2, subparagraph a) of the Regulation), taking into account the short duration of the violations and the small number of data subjects involved;

- as an aggravating factor, (Article 83(2)(b) of the Regulation) the significantly negligent nature of the violations, committed by a leading operator in the telecommunications sector—a company that possesses the necessary know-how to properly implement the provisions regarding data protection;

- as a mitigating factor, the measures adopted by the Company (monitoring of its partners’ activities, which also led to the termination of the relevant contracts; introduction of IT and organizational procedures) during the investigation to mitigate the harm, even potential harm, to data subjects (Article 83(2)(c) of the Regulation);

- as an aggravating factor, the degree of the Company’s accountability (Article 83, para 2, subparagraph d), of the Regulation), taking into account the specific characteristics of the telemarketing sector—which is characterized by a large and pervasive “underground” market—and the risks posed to the personal data of customers and potential customers;

- as an aggravating factor (Article 83(2)(e) of the Regulation), the numerous prior violations, including specific ones, committed by the Company;

- as a mitigating factor (Article 83(2)(f) of the Regulation), the Company’s high instance of cooperation, evidenced by the fact that TIM S.p.A. provided the Data Protection Authority—including during the course of the inspections—with detailed responses, supplying a comprehensive set of information that enabled a thorough assessment of the entire range of processing activities;

- as a further mitigating factor (Article 83(2)(g) of the Regulation), the fact that the violations did not involve special categories of data within the meaning of Article 9 of the Regulation;

- as a mitigating factor (Art. 83(2)(j) of the Regulation), compliance with the code of conduct for telemarketing activities;

- as a mitigating factor (Art. 83(2)(k) of the Regulation), the substantial investments made by the Company to implement control procedures throughout the sales chain aimed at minimizing unlawful conduct.

Based on all of the above factors, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Art. 83(1) of the Regulation, it is deemed appropriate to impose on TIM S.p.A. an administrative fine of 9,516,000.00 euros, equal to 1.7% of the maximum statutory fine.

In the case at hand, it is deemed appropriate to impose the ancillary sanction of publishing this decision on the Authority’s website, as provided for in Article 166, paragraph 7 of the Code and Article 16 of the Authority’s Regulation No. 1/2019, taking into account the nature of the processing operations, as well as the risks to the data subject rights and freedoms.

Finally, the conditions set forth in Art. 17 of Regulation No. 1/2019 regarding internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, are met.

NOW THEREFORE, THE DATA PROTECTION AUTHORITY

- pursuant to Article 57(1)(a) and (f) of the Regulation, declares the processing of personal data carried out by TIM S.p.A., in the person of its pro tempore representative, with registered office in Milan, Via Gaetano Negri 1, Tax ID 00488410010, for violating Articles 5, 6, 7, 12, 15 through 22, 24, 25, 28, and 32 of the Regulation, as well as Art 130 of the Code, as set forth in the reasoning;

- orders TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to implement corrective measures in the customer follow-up procedure following requests submitted through the Company’s or its partners’ web pages, in order to prevent the mass submission of phone numbers for follow-up contact and to ensure that consent for such contact has been provided by the actual data subject;

- orders TIM S.p.A., pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adopt adequate measures to monitor and supervise the activities of its partners and to ensure that promotional activities carried out on behalf of the Company are conducted in full compliance with personal data protection regulations;

- orders TIM S.p.A., pursuant to Art 58, para 2, subparagraph d) of the Regulation, to adapt the procedures designed to ensure the exercise of the rights under Articles 15–22 of the Regulation, in order to prevent or at least significantly reduce instances of failure to respond, delayed responses, and systematic extensions of deadlines;

- orders TIM S.p.A., pursuant to Article 58, para 1, subparagraph (a) of the Regulation and Article 157 of the Code, to notify the Authority, within thirty days of the service of this order, the steps taken to implement the measures imposed;

ORDERS

TIM S.p.A., in the person of its pro tempore representative, with registered office in Milan, Via Gaetano Negri 1, Tax ID No. 00488410010, to pay the sum of 9,516,000.00 euros (nine million five hundred sixteen thousand/00) as an administrative fine for the violations set forth in the grounds of this decision, noting that the offending party, pursuant to Article 166, paragraph 8, of the Code, has the right to settle the dispute by complying with the requirements set forth and paying, within thirty days, an amount equal to half of the penalty imposed.

ORDERS

the aforementioned Company, in the event of failure to settle the dispute pursuant to Article 166, paragraph 8, of the Code, to pay the sum of 9,516,000.00 euros (nine million five hundred sixteen thousand/00), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the Authority will take the necessary enforcement measures pursuant to Art. 27 of Law No. 689/1981.

ORDERS

a) pursuant to Article 154-bis of the Code and Article 37 of the Data Protection Authority’s Internal Regulation No. 1/2019, the publication of this order on the Data Protection Authority’s website;

(b) pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Internal Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website;

c) pursuant to Article 17 of the Authority’s Internal Regulations No. 1/2019, the entry in the Authority’s internal register, as provided for in Article 57, para 1, letter u) of the Regulation, of the violations and the measures adopted;

Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the place where the controller of personal data resides, or, alternatively, with the court of the place of residence of the data subject, within thirty days from the date of notification of this decision, or within sixty days if the appellant resides abroad.

Rome, July 23, 2026

THE CHAIRMAN
Stanzione

THE RAPPORTEUR
Stanzione

THE SECRETARY GENERAL
Montuori