Key Takeaways
- On 31 July 2026 Italy's Garante announced a €9,516,000 fine against TIM, over a decision dated 23 July 2026, for a telemarketing chain in which partners placed unlawful calls and then manufactured the paperwork that made those calls look consented.
- The partners sent an SMS link that produced a fictitious "Lead" — a step the Garante described as designed to "cleanse" the data chain as regards the parent company.
- Adherence to an approved code of conduct did not shield TIM. The Garante treated it as a factor in calibrating the penalty, not a defence — and Article 24(3) says the same, calling codes "an element by which to demonstrate compliance", not proof of it.
- Under Article 7(1) the burden of proving consent sits with you, the controller. The EDPB is explicit that pointing at a correctly configured form is not enough: "It would not be sufficient to merely refer to a correct configuration of the respective website."
- TIM is a telecoms company, not an online retailer, and no equivalent eCommerce case exists yet. The duties applied are general ones — which is why a store buying leads should read this decision as being about itself.
Introduction
Say your agency hands you a spreadsheet of 4,000 leads and tells you they are all opted in. You import them on Tuesday, and by Friday you have your first complaint. The uncomfortable question is not whether the agency lied. It is what you can actually produce if a regulator asks you to prove those 4,000 people said yes.
Italy's data protection authority spent July answering a version of that question, and the answer cost €9.5 million. The decision concerns a telecoms giant's call centres, not a Shopify store — but the rules it applies govern every merchant who has ever bought a list, hired an agency, or run an affiliate programme.
This is informational content, not legal advice.
Who Is Liable When a Marketing Vendor Collects Consent?
You are. If a vendor collects personal data for your marketing purposes, you are the controller, and Article 7(1) puts the burden of demonstrating valid consent on you. A vendor's assurance that consent was obtained is not evidence of consent — it is a claim you must substantiate yourself.
What the Garante actually found
In a press release dated 31 July 2026, the Garante announced a €9,516,000 fine against TIM, following provvedimento n. 556 of 23 July 2026. The conduct had three moving parts.
First, promotional calls for TIM services reached numbers on Italy's public opt-out register, the Registro Pubblico delle Opposizioni, placed by operators who disguised the calling line — a technique the decision calls "manipolazione del CLI (CLI spoofing)".
Second, and more instructive for marketers, came the paperwork. The press release describes the "invio ai clienti interessati, tramite SMS, di un link ipertestuale collegato a una pagina web di un partner ufficiale della rete di vendita TIM, contenente un modulo che l'utente è invitato a compilare per formulare un'autonoma richiesta di ricontatto (cosiddetta 'Lead')" — sending the contacted person an SMS link to a form on an official TIM sales-network partner's web page, which the user is invited to fill in to make an autonomous request to be re-contacted.
The Garante was not fooled by the sequence. Its finding is the sentence every marketer should read twice:
"Tale operazione era preordinata a generare una fittizia richiesta autonoma di ricontatto (Lead), idonea a 'ripulire' la filiera del dato nei confronti della casa madre."
Literally: the operation was arranged in advance to generate a fictitious autonomous request to be re-contacted, apt to "cleanse" the data chain as regards the parent company. The scare quotes around ripulire are the Garante's own.
Third, the maths gave it away. In a November 2024 snapshot, one partner declared 17,388 leads against 22,242 contacts placed; another declared 6,075 against 16,102 — a surplus of more than 10,000 contacts over declared requests. Partner names are redacted in the published decision. A genuine Lead, the authority reasoned, "presuppone una richiesta autonoma, mirata e consapevole da parte del singolo utente" — presupposes an autonomous, targeted and conscious request by the individual user — so a surplus of that size, alongside very low conversion, showed the lists were not genuine.
Treat that as an evidentiary method, not a threshold: the Garante inferred fabrication from the mismatch, and published no conversion rate below which a list is presumed bad.
Why "our partner had consent" is not a defence
The Garante's own words on supervision are unambiguous. In the press release: "l'adesione a un codice di condotta – ha ribadito il Garante - non esonera il titolare del trattamento dall'obbligo di vigilare sull'operato dei propri partner" — adherence to a code of conduct does not exempt the controller from the obligation to supervise the conduct of its own partners.
In the decision, the authority located the fault precisely: "L'omissione di tali siffatti presidi integra, a tutti gli effetti, la sussistenza della colpa in capo al titolare" — the omission of such safeguards constitutes, for all purposes, the existence of fault on the part of the controller. It framed this as culpa in vigilando and culpa in eligendo: fault in supervising, and fault in choosing.
Here is the honest limit of the case. TIM is a telecommunications company. The Garante did not rule on eCommerce, and no equivalent enforcement action against an online retailer over vendor-sourced consent has been published. But the provisions the authority applied — Articles 5(2), 7, 24 and 28 among them — bind every controller regardless of sector. A merchant who reads this as a telecoms story is reading it wrong.
Does a Code of Conduct or a Contract Clause Protect You?
No. A code of conduct or a warranty clause can reduce a penalty and shift money between you and your vendor, but neither transfers the legal duty. GDPR Article 24(3) treats adherence to approved codes as one element by which a controller may demonstrate compliance — not as compliance itself, and not as a defence.
The Regulation's wording is deliberate. Article 24(3) provides that adherence to approved codes of conduct or certification mechanisms "may be used as an element by which to demonstrate compliance with the obligations of the controller." An element — not a substitute.
TIM argued its membership of Italy's telemarketing code of conduct, approved 7 March 2024, showed compliance. The Garante's response draws the line exactly where the Regulation does:
"L'adesione può certamente essere valutata dall'Autorità per calibrare l'intensità della sanzione (in senso attenuante, ex art. 83, par. 2, lett. j del Regolamento), ma non cancella l'illecito commesso né preclude l'intervento correttivo."
Adherence may be assessed in calibrating the intensity of the sanction, as a mitigating factor under Article 83(2)(j), but it erases neither the infringement nor the authority's power to order corrections.
There is a sharper irony in the file: the code TIM invoked already required what TIM had not done. It obliges the controller to ensure "il pieno, puntuale e costante controllo dell'intera filiera" — full, timely and constant control of the entire chain of parties involved in any preparatory or execution phase of a promotional campaign.
Contractual indemnities sit in the same category. An agency executive, speaking anonymously to Digiday, described large clients sending updated master service agreements that make the agency assume responsibility and add "we won't indemnify you if something is noncompliant". That is a commercial allocation of loss, not a reallocation of controllership — and a supervisory authority is not a party to it.
What Proof of Consent From a Vendor Must Actually Contain
A defensible record shows how consent was obtained, when it was obtained, and what the person was actually shown at that moment. The EDPB requires all three. A vendor export listing an email address, a timestamp and the word "yes" satisfies none of them, because it cannot reproduce the notice the person read.
The EDPB's Guidelines 05/2020 on consent set the standard at paragraph 108: the controller "may keep a record of consent statements received, so he can show how consent was obtained, when consent was obtained and the information provided to the data subject at the time shall be demonstrable." The same paragraph closes the obvious escape route: "It would not be sufficient to merely refer to a correct configuration of the respective website."
That single sentence is the one to quote back to a vendor. "Our form is set up correctly" is precisely the answer the EDPB has said does not work.
| What you usually get from a vendor | What Article 7(1) and EDPB ¶108 need |
|---|---|
| "All contacts are opted in" | A per-record demonstration that this person consented |
| Email address plus a date | Timestamp and the collection method it came from |
| A screenshot of the current form | The exact notice text and consent wording shown at the time |
| "We comply with GDPR" | Evidence the workflow met every criterion for valid consent |
| A signed warranty in the contract | Records you can produce yourself, without the vendor's cooperation |
Two further constraints matter when you inherit a list. The EDPB holds that pre-ticked opt-in boxes are invalid and that "[s]ilence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice" — so ask what the affirmative act actually was. And consent does not keep indefinitely: there is no fixed statutory limit, but the EDPB states that if processing operations "change or evolve considerably then the original consent is no longer valid", and recommends refreshing it at appropriate intervals. A list collected for one company's newsletter has not consented to yours.
One counterweight, because it is easy to overcorrect: paragraph 106 warns that demonstrating consent "should not in itself lead to excessive amounts of additional data processing." Collect enough to show the link to the processing, not a dossier on every subscriber.
How to Audit a Marketing Vendor Before You Use Their List
Run this before the first send, not after the first complaint. Steps 1 to 4 are the ones that would have surfaced the TIM pattern.
- Ask for the notice, not the assurance. Request the exact consent wording and privacy notice displayed at collection, with the date range each version was live. If the vendor cannot produce versioned notice text, you cannot demonstrate consent and should not mail the list.
- Reconcile volumes against activity. Ask how many people were contacted to produce the leads you are buying. A large gap between outreach and declared opt-ins is the signal the Garante relied on, and a vendor unwilling to share the denominator is telling you something.
- Establish the affirmative act. What did the person physically do — tick an unticked box, submit a form, reply to a message? If the answer involves a pre-ticked box, silence, or "they didn't object", the consent is invalid on the EDPB's stated position.
- Check who they consented to. Consent runs to a named controller and purpose. If the notice said "our partners", ask whether your company was identified at the time. If it was not, that consent does not cover you.
- Use the audit right you already have. Article 28(3)(h) requires processors to make available all information necessary to demonstrate compliance and to "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." It is already in every compliant data processing agreement, and most merchants never invoke it.
- Record the vendor in your processing records. Every marketing vendor, affiliate network and list source belongs in your record of processing activities, with its role and lawful basis.
- Test the exit before the entry. Send yourself through the unsubscribe path the vendor's traffic will use. Article 7(3) requires that it be as easy to withdraw as to give consent.
- Re-run steps 1 to 3 periodically. Article 24(1) requires that measures be "reviewed and updated where necessary". Onboarding diligence that is never repeated is exactly the culpa in vigilando the Garante described.
Common Mistakes
Treating the contract as the control. This is the worst of them, because it feels like diligence. A warranty clause allocates money after something goes wrong; it does not produce one record you can hand a regulator. Sign the clause, then collect the evidence anyway.
Auditing at onboarding and never again. The TIM findings describe an ongoing supervision failure, not a bad procurement decision. Article 28(1) requires you to use only processors providing "sufficient guarantees", and a guarantee verified once in 2024 is not evidence about 2026.
Assuming the DSAR problem is somebody else's. The findings were not confined to acquisition. The Garante described "sistematica inosservanza ... degli obblighi in materia di esercizio dei diritti degli interessati" — systematic non-compliance with data subject rights obligations — through omitted or delayed responses to access, erasure and objection requests. The decision records one access request answered after 120 days, another after 85, and one file where marketing email continued for more than four months after the person objected. When a vendor sources your contacts, the rights requests still land in your inbox. Automating DSAR intake keeps a 120-day response from becoming your story.
Building an unsubscribe route only your customers can use. The Garante found TIM's opt-out route obstructive: it required virtual assistants, app downloads and account credentials, which locked out non-customers who had no credentials at all. If your list came from a vendor, most of those people are not your customers. An unsubscribe flow behind a login is no unsubscribe flow.
Confusing your own consent records with inherited ones. These are different evidentiary problems. Our guide to proof-of-consent records covers what to capture when you collect consent yourself; everything above is what to demand when somebody else collected it for you.
How PrivacyForge Helps
The difficulty with vendor-sourced consent is not knowing the rule. It is that the evidence lives in someone else's system, and you discover that on the day you need it.
PrivacyForge keeps consent records on your side of the line: timestamped, versioned against the notice text that was actually shown, and exportable as evidence rather than as a marketing report. Data mapping treats third parties as first-class entries, so an agency or affiliate network appears in your record of processing activities with its role and lawful basis instead of quietly becoming a gap. DSAR workflows track statutory deadlines from receipt — which matters most for contacts you did not collect yourself, since those people are the likeliest to object.
None of that stops a vendor fabricating a lead. It does mean you can tell, and can show a regulator which records you hold and which you never received.
Frequently Asked Questions
Am I liable if my marketing agency or lead-gen vendor collected consent unlawfully?
Yes. Where a vendor collects data for your marketing purposes, you are the controller, and Article 7(1) puts the burden of demonstrating consent on you. Italy's Garante fined TIM €9,516,000 in a decision announced on 31 July 2026 partly for failing to supervise partners who fabricated leads. The vendor's conduct does not transfer your duty.
Does a contract clause saying the vendor guarantees GDPR compliance protect me from a fine?
No. A warranty or indemnity allocates financial loss between you and the vendor; it does not move controllership or satisfy your obligation to demonstrate consent. A supervisory authority is not a party to your contract. Sign the clause if you want the commercial protection, but collect the underlying consent records yourself — they are what a regulator will ask for.
Does belonging to an approved code of conduct mean I do not have to supervise my marketing partners?
No. The Garante held that adherence to a code of conduct does not exempt a controller from supervising its partners' conduct, treating it as a mitigating factor under Article 83(2)(j) rather than a defence. GDPR Article 24(3) frames codes the same way — as "an element by which to demonstrate compliance", not compliance itself. Supervision remains an ongoing obligation.
Can I use a purchased or "opted-in" email list from a list provider for my online store?
Only if you can demonstrate that each person consented to being contacted by you specifically, for your purpose. Consent runs to a named controller and purpose, so an opt-in given to another company's newsletter does not cover your store. If the provider cannot supply the notice text shown at collection and a per-record timestamp, you cannot meet Article 7(1).
What evidence should I ask a lead-generation vendor for before I import their list?
Ask for three things: the exact consent wording and privacy notice shown at collection with version dates, a per-record timestamp and collection method, and the number of people contacted to produce the leads. The EDPB is explicit that it "would not be sufficient to merely refer to a correct configuration of the respective website", so a screenshot of the current form is not evidence.
How long does consent from a third-party vendor stay valid?
The GDPR sets no fixed expiry. The EDPB states that how long consent lasts depends on context, scope and the data subject's expectations, and that if processing operations change or evolve considerably the original consent is no longer valid. It recommends refreshing consent at appropriate intervals. Treat an undated or years-old vendor list as unusable until re-permissioned.
Conclusion
The TIM decision is worth your attention not because a telecoms company was fined, but because of what the Garante refused to accept: a code of conduct, a partner's paperwork, and a form that produced the right-looking record. The authority looked past all three to ask whether the people on the list had genuinely asked to be contacted.
Ask that of your own vendor lists. The honest answer for most merchants is that they could not currently prove it either way. Start with the notice text: if your vendor cannot produce the exact wording someone saw on the day they opted in, you do not have consent — you have a spreadsheet.
Start a free PrivacyForge trial to keep consent records, vendor registers and DSAR deadlines on your side of the chain.
Sources
- Garante press release, 31 July 2026 — TIM sanction
- Garante, provvedimento n. 556 of 23 July 2026
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679
- GDPR Article 7 — Conditions for consent
- GDPR Article 24 — Responsibility of the controller
- GDPR Article 28 — Processor
- Digiday — Confessions of a digital agency exec on brands shifting GDPR liability to agencies