The decision of the Italian Data Protection Authority dated September 12, 2024, that sanctions Sky Italia S.r.l. (SKY) for unlawful telemarketing activities represents a pivotal moment in the field of personal data protection in Italy.
The decision in question stems from a series of complaints by users regarding alleged unlawful telemarketing activities and issues with consent management by SKY. We believe that our comment could help to identify the minimum guide lines to be followed by the operators in the marketing and communications sector.
Through this decision, the Italian Data Protection Authority issues a sanction against SKY’s conduct, which committed multiple violations of both European and national data protection regulations. In addition the Italian Data Protection Authority detects an evident breach of Article 130 of the Italian Privacy Code concerning the Public Opt-Out Register (RPO).
In particular, the Italian Data Protection Authority highlighted:
In this decision, the Italian Data Protection Authority imposed a series of specific corrective measures on SKY to remedy the violations, including:
In addition to these corrective measures, the Italian Data Protection Authority imposed a financial penalty of €842,062.00, equivalent to 1% of the maximum penalty by law, deemed proportionate to the seriousness of the infringements. The publication of the decision was also ordered as a deterrent.
Sanctions took into account both aggravating factors (such as recidivism, referencing a previous decision from 2021) and mitigating factors (particularly SKY’s cooperation during the investigation).
The Italian Public Opt-Out Register has been set as a fundamental tool for protecting consumers from unsolicited promotional communications, even if it seems not to block completely the phenomenon.
According to the Italian law companies must verify in advance whether users are registered in the RPO before making calls or sending advertising SMS.
However, in SKY’s case, a significant deficiency in these checks was revealed, leading to numerous violations confirmed by the Italian Data Protection Authority.
Specifically, the Italian Data Protection Authority found that SKY contacted several people listed in the RPO for advertising purposes, in plain infringement of Article 130 of the Privacy Code and Articles 5 and 6 of the GDPR.
Additionally, some of the unsolicited communications were carried out by third-party suppliers engaged by SKY, who failed to consult their respective blacklists in advance. On this point, the Italian Data Protection Authority clarified that SKY remains jointly liable for failing to adequately supervise its partners.
The decision against SKY provides valuable insights for companies, including those operating in the telemarketing field.
In another article, we have already highlighted the importance for companies to conduct their marketing campaigns responsibly.
Additionally, we highlight that, the prior check of the Public Opt-Out Register should not be seen as a mere formality during the development of each marketing campaign. Instead it should be an essential step to ensure regulatory compliance and protect the rights of data subjects as per Italian privacy law.
Consequently, companies must exercise a strict control over the suppliers entrusted to process personal data, ensuring they operate in compliance with current regulations. To this purpose, periodic audits can help to prevent similar violations and also allow companies to promptly identify potential issues in their processes.
The SKY case is an emblematic example of the consequences of inefficient personal data management and non-compliance with data protection regulations in the field of marketing and communication.
The failure to adhere to the rules governing the Public Opt-Out Register highlights the need for companies to adopt a more rigorous approach. Because compliance is not only a legal obligation but also a strategic factor for building trust and reputation.
Finally, the decision of the Italian Data Protection Authority which sanctions SKY underscores the importance of strict application of personal data protection rules. It is fundamental to safeguard the rights of data subjects and to promote a responsible corporate culture. For companies, this case serves as a warning to review and strengthen their internal procedures. The respect for regulations and users’ fundamental rights has to be at the center of their marketing initiatives.