← Enforcement
GDPR EU 2016/679 Italy

Garante fines: Italy's war on telemarketing — and on management by algorithm

A registry of the largest GDPR fines from Italy's Garante — Enel Energia €79.1M and €26.5M, TIM €27.8M, Wind Tre €16.7M, Vodafone €12.25M — plus the pioneering gig-economy cases against Foodinho and Deliveroo. Why Italy's enforcement is dominated by unsolicited marketing calls and worker-management algorithms, and what each company did. Every amount sourced to the regulator.

Italy’s Garante is one of the most aggressive data regulators in the EU, and its fine list has a very particular shape. Strip out the famous AI cases — the world-first ChatGPT block and the Garante’s AI fines — and what is left is dominated by two themes most other regulators barely touch: unsolicited telemarketing and management of workers by algorithm.

This is the registry of those GDPR fines: the telecoms and energy giants punished for phone-marketing people who never consented, and the gig-economy platforms fined for letting an algorithm rate, rank and penalise riders. Every figure links to the regulator or the EU mirror of its decision.

Why telemarketing dominates the Italian list

In Italy, unsolicited marketing calls are a genuine social plague, and the Garante has spent years going after it — with dedicated sections of its annual report on illegal telemarketing in the telecoms sector, the energy sector and beyond (Garante, Relazione 2024). The recurring violations are the same across every case:

  • calling people who never gave consent, or who were on the public opt-out register (the Registro Pubblico delle Opposizioni);
  • buying contact lists from third parties without checking how that consent was obtained;
  • failing to control an outsourced sales network that generated calls — sometimes from fake or unregistered phone numbers, sometimes on forged contracts.

The second Italian speciality is newer and more forward-looking: the Garante was among the first regulators anywhere to fine a company for algorithmic management — using an automated system to score and discipline gig workers without transparency or a right to human review.

Quick guide to the GDPR provisions below:

  • Art. 5–6 — the principles and the need for a valid lawful basis (here, almost always consent for marketing).
  • Art. 13–14 — telling people clearly how their data is used.
  • Art. 22 — the right not to be subject to purely automated decisions with significant effects — the heart of the gig-worker cases.
  • Art. 25 — data protection by design and by default.
  • Art. 28 — a controller’s duty to control its processors (the outsourced call centres and sales agencies).

The registry — by amount

1. Enel Energia — €79,100,000 — 8 February 2024 — Italy’s record GDPR fine

The largest GDPR fine the Garante has ever imposed. Four companies promoted Enel’s electricity and gas contracts without any authorisation from Enel, using forged forms and identification documents; Enel then used the personal data tied to at least 9,300 contracts obtained this way. The Garante found Enel had failed to control the agencies operating in its name.

Articles. Article 5 and Article 25 (accountability, privacy by design), Article 28 (failure to control processors) over its “N.Eve” platform.

Status. Enel announced it would appeal.

Source: DataGuidance — Garante fines Enel Energia €79.10M.


2. TIM — €27,802,496 — 15 January 2020

For years the record Italian fine. From January 2017 to early 2019 the Garante received hundreds of complaints about TIM’s unsolicited marketing calls — placed without consent, or in spite of the recipients being on the public opt-out register, plus invalid consents and excessive retention.

Articles. Article 5, Article 6/7 (consent) and transparency duties.

Source: EDPB — Italian SA fines TIM €27.8 million.


3. Enel Energia — €26,500,000 — 16 December 2021

A separate, earlier Enel case (do not confuse it with the €79.1M 2024 fine above). After hundreds of complaints about unsolicited calls made on Enel’s behalf — some using pre-recorded messages — the Garante fined Enel for aggressive telemarketing and breach of the accountability principle.

Articles. Article 5 (accountability) and the lawful-basis and consent rules for marketing.

Source: EDPB — Italian SA fines Enel Energia €26.5 million.


4. Clearview AI — €20,000,000 — 2022

For scraping Italians’ facial images without a legal basis. Part of the cross-regulator story told in full in the Clearview AI fines registry.

Articles. Articles 5, 6 and 9 (no legal basis, special-category data) and data-subject rights.

Source: Clearview AI fines registry.


5. Wind Tre — €16,729,600 — 9 July 2020

The telecoms operator was fined for unlawful direct marketing — users received unsolicited texts, emails and automated calls without consent — and the Garante banned further processing of the data acquired without consent. (The same day, the Garante also fined Iliad €0.8 million.)

Articles. Article 5, Article 6/7 (consent) and Articles 13–14 (information).

Source: EDPB — Italian SA fines Wind €17 million and Iliad €0.8 million.


6. Vodafone Italia — €12,250,000 — 12 November 2020

For unlawfully processing the data of millions of users for telemarketing, after hundreds of complaints about unsolicited calls from Vodafone and its sales network. A striking finding: calls were placed from fake phone numbers not registered with the ROC, Italy’s official register of communications operators.

Articles. Article 5, Article 6 (consent) and processor-control duties.

Source: EDPB — Vodafone fined over €12 million by Italian DPA.


7. Foodinho (Glovo) — €2,600,000 — July 2021 — the algorithm case

A landmark. The Glovo-owned delivery platform Foodinho was fined for how its algorithm managed riders: it scored and ranked workers without telling them how the system worked, did not guarantee the accuracy of those algorithmic ratings, and provided no way for a rider to obtain human review or contest an automated decision. One of the first GDPR fines anywhere aimed squarely at management by algorithm.

Articles. Article 5, Article 13 (transparency) and Article 22 (automated decision-making).

Source: EDPB — Italian SA: no to algorithms causing discrimination; Glovo-group platform fined €2.6 million.


8. Deliveroo Italy — €2,500,000 — 2021

Issued in the same wave of scrutiny of gig-economy platforms. Deliveroo’s Italian arm was fined €2.5 million over how it handled riders’ data and the algorithm used to manage them — inadequate transparency about the automated systems that governed their work.

Articles. Article 5, Article 13 (transparency) and Article 22 (automated decision-making).

Source: TechCrunch — Italy’s DPA and the gig-economy algorithm fines.


Two patterns, one regulator

The Garante’s list tells you what Italy’s regulator actually cares about:

  • Telemarketing is the bulk of the money. Enel (twice, including the €79.1 million record), TIM, Wind Tre, Vodafone, Iliad — the biggest Italian fines are overwhelmingly about calling people who didn’t consent, and about companies failing to police the outsourced agencies and call centres acting in their name. If you run any kind of outbound marketing into Italy, this is the case law that applies to you.
  • Algorithmic management was pioneered here. The Foodinho and Deliveroo fines put the Garante among the first regulators in the world to say that an automated system rating and disciplining workers is a GDPR matter — it needs transparency, accuracy, and a human a worker can appeal to. As AI moves into HR and hiring, these cases are the template.

For the Garante’s separate, equally pioneering AI line — the ChatGPT block and the OpenAI and Replika fines — see the dedicated Garante AI fines registry.

What this means if you operate in Italy

  • Don’t call or message without provable consent — and check the opt-out register. Every telecom and energy fine above comes down to this. Consent must be specific, documented, and respected against the Registro Pubblico delle Opposizioni.
  • You are responsible for your sales network. Enel’s €79.1 million fine was, at its core, for not controlling the agencies generating contracts in its name. “Our partners did it” is the opposite of a defence under Article 28.
  • If an algorithm rates, ranks or penalises people, treat it as Article 22. Workers (and customers) have a right to know the logic, to accurate inputs, and to a human who can review the decision. Building an automated scoring system without those is exactly what cost Foodinho and Deliveroo.

The structural fix is unglamorous: clean, documented consent; real oversight of the third parties acting for you; and human review built into any automated decision that affects someone materially.

Sources for independent verification

Short conclusion

Italy’s Garante fines for two things almost no one else makes headlines over: unsolicited marketing calls and management by algorithm. The telemarketing fines — led by the €79.1 million Enel record — punish companies for calling people who never consented and for not controlling the agencies doing it; the Foodinho and Deliveroo cases made worker-rating algorithms a GDPR question before most regulators had noticed. If you market into Italy or automate decisions about people there, this is the list to read before, not after.