
Italy's data protection authority has fined telecommunications giant TIM €9.516 million ($11 million) after finding widespread privacy and telemarketing violations involving unlawfully obtained customer consent, inadequate oversight of third-party sales partners, and failures to properly handle users' data protection requests.
The regulator also ordered the company to strengthen its sales network controls and improve its lead generation and privacy procedures.
The Italian Data Protection Authority (Garante per la protezione dei dati personali) announced the decision following an investigation prompted by approximately 7,000 complaints received during 2025 about unwanted promotional calls made on behalf of TIM. The authority found that unauthorized call centers were using deceptive practices to market TIM services while unlawfully collecting consumers' personal data.
The investigation, which included inspections of TIM's telemarketing operations, uncovered a scheme designed to disguise illegal marketing contacts as legitimate customer requests. According to the Garante, TIM failed to adequately supervise partners across its telemarketing supply chain and ensure compliance with data protection rules.
TIM is one of Italy's largest telecommunications providers, serving millions of mobile, broadband, fixed-line, and enterprise customers through an extensive network of sales partners and contractors.
According to the regulator, the scheme began with unsolicited calls made using spoofed or unregistered phone numbers, often targeting consumers enrolled in Italy's Public Register of Objections (RPO), which allows users to opt out of telemarketing calls. Callers posed as authorized TIM representatives and promoted the company's services.
Interested consumers then received an SMS containing a link to a webpage operated by an official TIM sales partner, where they were asked to submit a contact request. The authority said this created a fictitious “lead” that allowed a registered call center to contact the individual using a legitimate phone number, making the subsequent sales process appear compliant despite originating from an unlawful call.
The Garante rejected TIM's argument that its participation in an industry code of conduct constituted adequate compliance, reiterating that data controllers remain responsible for monitoring their partners and ensuring that personal data is processed lawfully throughout the telemarketing chain.
The authority also found that TIM repeatedly failed to comply with data subject rights by responding late or not at all to requests for access, deletion, and objections to processing. It further criticized the company's unsubscribe procedures as unnecessarily complex and, in some cases, non-functional.
Alongside the €9.516 million fine, the Garante ordered TIM to strengthen oversight of its sales network, introduce safeguards to its lead generation process, and improve procedures for handling privacy requests.







Leave a Reply