The case, explained

Aggressive Telemarketing: Controller Liability for Supply Chain Violations

7 min read · Updated September 2026 · Editorial oversight: Avv. Federico Papa

The recent development of February 2024 marks a point of no return in compliance management for large sales networks. According to press reports, the measure against a well-known energy company scrutinizes not just individual harassing calls, but the entire control architecture a large company must exercise over its business partners and external agencies. While other profiles related to emerging technologies or sensitive data have been covered in dedicated articles, this case focuses exclusively on commercial chain oversight. The story stems from an extensive investigation that revealed a chain of non-consensual contacts, acquired through illegal databases and fed into the corporate system via unauthorized agencies. Through the twin case of Gaio Sventura, we will explore how negligence in process organization can turn into strict or quasi-strict liability for the data controller, regardless of direct awareness of individual violations committed by sub-contractors.

Aggressive Telemarketing: Controller Liability for Supply Chain Violations

In brief

The article analyzes the sanction imposed by the Privacy Guarantor on a well-known energy company for unlawful telemarketing, focusing on the data controller's liability for violations committed within the commercial chain. It examines the accountability obligation and oversight, highlighting how the failure to implement effective monitoring systems leads to sanctions based on global turnover. The case clarifies the boundary between third-party fraud and the company's organizational negligence.

  1. The facts

    According to reports from outlets such as Rai News, Wired Italia, and Il Sole 24 Ore, the Data Protection Authority imposed a fine of over 79 million euros on a well-known energy company following an investigation triggered by the Italian Financial Police's findings on illegal databases. The case concerns the so-called black chain of telemarketing, a network of agencies that, without a direct mandate, acquired contracts using illicitly obtained data and entered them into the company's systems through partner channels. Currently, the company's opposition against the measure has been rejected by the Court of Rome (judgment no. 12783/2025), confirming the fine. The company's defense argued it was a victim of fraudulent conduct by unfaithful agencies that bypassed existing controls.

  2. The rules at play

    The legal framework centers on the accountability principle introduced by EU Regulation 2016/679 (GDPR).

    1. Article 24 of the GDPR requires the data controller to implement appropriate technical and organizational measures to ensure and demonstrate that processing is performed in compliance with the regulation.
    2. Article 28 governs the relationship with data processors, requiring the controller to use only those providing sufficient guarantees and to supervise their work and that of the commercial chain.
    3. Article 25 provides for privacy by design, mandating that IT systems (such as partner portals) be configured to natively prevent the entry of unverified data.
    4. Article 32 imposes security of processing, which in telemarketing translates into the ability to intercept anomalous contract flows from untracked sources.
  3. What case law says

    The orientation of higher courts has clarified that the data controller holds a position of guarantee that does not vanish with the outsourcing of promotional activities. According to the courts, a service or agency contract does not sever the liability link if the controller derives an economic benefit from the unlawful processing and fails to prove having taken every possible precaution to prevent it. European case law has also specified that the notion of controller must be interpreted broadly: anyone determining the purposes and means of processing (even indirectly, by accepting contracts from an uncontrolled chain) is liable for systemic violations. Therefore, a contractual indemnity clause is not enough to exclude so-called culpa in vigilando if the data entry systems are vulnerable to massive uploads by unauthorized parties.

  4. Analysis drafted and verified with edit.legal

    To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.

    Try edit.legal AI
  5. What it teaches professionals

    1. Implement inspection and audit clauses in marketing agency contracts, including the right to physically or digitally verify the origin of consent.
    2. Adopt data entry systems requiring mandatory metadata on source traceability for every single record submitted.
    3. Monitor sales KPIs to identify anomalous spikes in contracts that could signal the entry of unauthorized databases.
    4. Manage commercial chain liability not as a paper indemnity, but as an extension of one's own organizational accountability.
  6. Update and rectification note (17 September 2026)

    The previous version of this article incorrectly reported the involvement of 15 million data subjects and qualified the agencies as sub-processors under Art. 28, details not corresponding to the measure. Furthermore, it defined the measure as a final act, omitting the updated procedural stage. The text has been corrected and anonymized in the absence of retrievable public primary sources, specifying that the disputed contracts are about 9,300 (of which 978 from unauthorized agents) and updating the outcome with the rejection of the opposition (Court of Rome 12783/2025).

References: Regolamento UE 2016/679 (GDPR) Art. 24Regolamento UE 2016/679 (GDPR) Art. 28D.Lgs. 196/2003 (Codice Privacy) Art. 130Tribunale di Roma, sentenza n. 12783/2025

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAMContent drafted with AI support and subject to editorial source checks. Despite these controls, inaccuracies may remain: reports and rectification requests are welcome. Report a correction

Frequently asked questions

What happens if a company suffers fraud from a business partner?

The company remains liable to the Authority unless it proves it adopted security and control measures suitable for preventing or promptly intercepting the fraud itself.

How is the fine for aggressive telemarketing calculated?

The fine can reach up to 4% of the global annual turnover of the company, taking into account the gravity of the violation, the number of individuals affected, and the duration of the breach.

Can individual citizens claim compensation?

Yes, under Article 82 of the GDPR, anyone who suffers material or non-material damage from unlawful processing has the right to take civil action for compensation.

Verified legal research and drafting with edit.legal

Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.

Try edit.legal for free