The case, explained
Business Unit Transfers and Data Controller Status: The CercanumeriPro Case
8 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa
Business unit transfers involving digital platforms and databases raise a precise issue: whoever takes over the assets also takes over the role of data controller, with all the obligations that follow from the moment of succession. Decision no. 593 of 9 October 2025 by the Italian Data Protection Authority (doc. web no. 10193723) offers a concrete example: the transferee of a contact-list platform was fined for violations relating to the processing it itself carried out after the transfer, as the controller that succeeded the transferor. Through a reconstruction of the real events, based on the text of the decision, and an expressly educational twin case, this article examines what succession as controller actually entails and what precautions an acquirer of data-bearing assets should take.

In brief
With decision no. 593 of 9 October 2025, the Italian DPA fined FT Solutions S.r.l., transferee of the CercanumeriPro platform, for violations relating to the processing carried out by the company itself after succeeding as data controller. The decision does not attribute the transferor's prior violations to the transferee and does not characterise the transfer as evasive. The fine is 5,000 euros, equal to 0.025% of the statutory maximum, and is contained in an injunction order that may be challenged before the ordinary courts within the statutory deadline. Rectification note of 17 September 2026 at the end of the article.
The facts
As stated in decision no. 593 of 9 October 2025 (doc. web no. 10193723), the proceedings originated from a broader investigation conducted by the Authority into Realmaps S.r.l., which concluded with a separate decision of 16 January 2025 (doc. web no. 10110241). On 2 August 2024 the DPA also received a complaint concerning Tedor S.r.l., relating to unwanted calls from real estate agencies that reported having obtained the data from the website cercanumeripro.it. By deed of 7 August 2024, Tempo dell'Oro S.r.l., formerly Tedor S.r.l., transferred the business unit relating to the CercanumeriPro platform to FT Solutions S.r.l.; the latter, according to the company register, had been incorporated by deed of 7 May 2024, thus before the complaint. The DPA found that, as a result of the transfer, FT Solutions succeeded to the very position previously held by the transferor, namely that of data controller, and it established violations relating to the processing carried out by FT Solutions in that capacity. The proceedings concluded with an injunction order of 5,000 euros, which may be challenged before the ordinary courts within the statutory deadline.

What the decision does not say
For a correct reading of the decision it is also useful to clarify what it does not contain.
- The decision does not attribute to FT Solutions liability for prior violations committed by the transferor: the violations established concern processing carried out by the transferee in its own capacity as controller.
- The decision finds no evasive intent in the transfer, nor does it characterise the transfer as fraudulent, simulated or artificial; the wording describing the company as incorporated specifically to continue the processing concerns the continuation of the activity, not a finding of evasion.
- The decision does not use the notion of economic continuity as a criterion for attributing prior violations or sanctions, and it neither cites nor applies Article 2560 of the Civil Code or Article 33 of Legislative Decree 231/2001.
- As for Tedor's position, the decision recounts the complaint and the subsequent transfer, but the sanctioning proceedings concluded against FT Solutions alone.
The rules at play
The decision rests on data protection law.
- Articles 5 and 6 of the GDPR (EU Regulation 2016/679) on principles and lawfulness of processing.
- Article 83 of the GDPR on the conditions for imposing administrative fines.
- The Italian Privacy Code (Legislative Decree 196/2003), in particular Article 152 on challenges before the ordinary courts, Article 157 on the Authority's requests for information, and Article 166(8) on settlement by payment of half the fine. The amount of the fine, 5,000 euros, is indicated by the DPA as equal to 0.025% of the statutory maximum, taking into account mitigating factors such as the absence of prior corrective or sanctioning measures, the ordinary nature of the contact data processed and the company's limited economic capacity.
The academic debate, kept distinct from the case
At a general level, and without any basis in decision no. 593, scholars have long debated whether and to what extent business transfers affect administrative sanctions. That debate draws on Article 2560 of the Civil Code on the debts of the transferred business and Article 33 of Legislative Decree 231/2001 on the transferee's joint liability for monetary sanctions imposed on the transferor entity. In GDPR matters, the case law of the Court of Justice of the European Union, in C-807/21 Deutsche Wohnen and C-383/23 ILVA, has relied on the concept of an undertaking under Articles 101 and 102 TFEU for the purpose of calculating the amount of the fine, an aspect distinct from the conditions for attributing liability. These are useful coordinates for framing the issue in the abstract: in the CercanumeriPro case the DPA used none of these constructions, having fined the transferee for its own conduct.
- Try edit.legal AI
Analysis drafted and verified with edit.legal
To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.
What it teaches professionals
- Whoever acquires platforms or databases succeeds as data controller: compliance of one's own processing must be ensured from day one, without relying on the state in which the assets are delivered.
- Due diligence on the origin and legal bases of the data remains essential: not because the transferor's sanctions transfer automatically, but because data lacking a valid legal basis cannot be lawfully used by the transferee.
- Contractual indemnity clauses operate only between the parties and do not affect the controller's liability towards the Authority and data subjects.
- If a sanction is issued, promptly weigh the alternative between judicial challenge and settlement, keeping the statutory deadlines in mind.
Rectification note (17 September 2026)
A previous version of this article, published on 12 September 2026 on the basis of press sources, attributed to DPA decision no. 593/2025 findings that do not appear in it: the attribution to FT Solutions S.r.l. of the transferor's prior violations, a finding of evasive intent in the transfer, the use of economic continuity as a criterion of attribution, and the application of Article 2560 of the Civil Code and Article 33 of Legislative Decree 231/2001. The previous version also described the decision as final, whereas it is an injunction order open to challenge within the statutory deadline, and attributed to Tedor S.r.l. a finding of massive consent-less processing that the decision does not contain, as the proceedings concerned FT Solutions alone. The article has been entirely rewritten on the basis of the text of the decision (doc. web no. 10193723), following a notice from the company concerned received on 17 September 2026. The original version is preserved in the editorial records.
References: Regolamento UE 2016/679 (GDPR) artt. 5, 6, 83D.Lgs. 196/2003 artt. 152, 157, 166Provvedimento Garante n. 593 del 9 ottobre 2025 (doc. web n. 10193723)Provvedimento Garante del 16 gennaio 2025 (doc. web n. 10110241)CGUE C-807/21 Deutsche Wohnen; CGUE C-383/23 ILVA
Related cases

Frequently asked questions
Is a Newco liable for privacy violations committed by the transferor before the transfer?
In the case examined, the DPA did not attribute the transferor's prior violations to the transferee: it fined the transferee for violations relating to the processing it carried out itself after succeeding as controller. The general question of what happens to sanctions in business transfers is debated by scholars, but it was not addressed in the decision.
What is the deadline to appeal the DPA sanction?
The challenge must be filed before the ordinary courts within 30 days of notification of the decision, pursuant to Article 152 of the Italian Privacy Code and Article 10 of Legislative Decree 150/2011.
Can the buyer of a database use it freely?
No. From the moment of succession the buyer is the data controller and may use the data only with a valid legal basis, proper notices and adequate measures. Using data lacking these requirements exposes the buyer to sanctions for its own conduct, regardless of what the previous controller did.
Verified legal research and drafting with edit.legal
Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.
Try edit.legal for free