HomeSecurityWind Tre and Iliad: High fines for privacy violation

Wind Tre and Iliad: High fines for privacy violation

Fines were imposed on Iliad Italia SpA and Wind Tre SpAby the Guarantor for the Protection of Personal Data of Italy for privacy violations.

Wind Tre Iliad privacy breach

The two providers will have to pay high fines for violating the GDPR, which came into effect in May 2018.

The protection authority began investigating the two companies in 2019, following multiple reports it received regarding data by “Iliad Italia SpA”, “Wind Tre SpA” and “Merlini Srl”, a marketing company based in Ponsacco (PI), which is linked to Wind Tre.

According to the authority, “Iliad Italia” recorded data without their consent, when activating SIM cards. The company also allegedly violated the principles of ethics, correctness, transparency and integrity by storing this data for marketing purposes.

“Iliad Italia” was fined 800,000 euros for the violations, which represents 4% of the company’s annual turnover. For now, Iliad Italia SpA CEO Benedetto Levi has not made any statement on the matter.

Wind Tre, on the other hand, is required to pay a fine of almost 17 million euros for illegally processing its users' data for marketing purposes. The Authority found that the company sent a large number of emails, phone calls and SMS without users' consent. In addition, several users had requested the deletion of their contact data from Wind Tre's files, but the company ignored these requests.

Clarity

Finally, a fine of 200 thousand euros was imposed on the company “Merlini srl”, for violating the GDPR. Specifically, the marketing company violated the following points of the regulation:

(a) the nature, gravity and duration of the breach, taking into account the nature, object or purpose of the processing in question, as well as the number of data subjects affected by the damage and the level of damage suffered by them.

b) the intentional or negligent nature of the violation;

c) the measures taken by the data controller or data processor to limit the damage suffered by the interested parties;

f) the degree of cooperation with the supervisory authority to resolve the infringement and limit its potential negative consequences;

(k) any other aggravating or mitigating factors applicable to the circumstances of the case, for example the economic benefits gained or losses avoided, directly or indirectly, as a consequence of the infringement.

Source: SuspectFile

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS