Who Actually Signs the Consent Form?
$10.9 million.
That is the price Telecom Italia (TIM) has been asked to pay by the Italian regulator for a particular brand of creativity regarding GDPR. To the casual observer, it looks like another telco fine, a recurring theme in European regulatory news. But if you follow the paperwork, this isn't about a leaked database or a forgotten encryption key. It is about the manufacture of consent.
The mechanics were delightfully cynical. TIM didn't just ignore the rules; they built a system to spoof calls, laundering illicit leads into what appeared to be legitimate, consented marketing lists. In regulatory terms, they weren't failing to protect data; they were fabricating the legal basis for processing it.
Under GDPR, consent must be "freely given, specific, informed and unambiguous." It is supposed to be a clear affirmative act. TIM's approach suggests they viewed these requirements as optional suggestions, provided the final spreadsheet showed a 'Yes' in the consent column.
There is a wide gap between what a company tells its board about its compliance framework and what happens on the ground. The press release likely spoke of "rigorous data governance." The reality was a spoofing operation designed to bypass the very laws that governance is meant to uphold.
It's a classic case of treating the audit trail as the product rather than the record.
One might argue that in the high-pressure world of telecommunications marketing, some level of "aggressive lead generation" is industry standard. They might claim that a few spoofed calls are a minor deviation in a sea of millions of interactions.
That argument fails because it ignores the systemic nature of the fraud. When you automate the faking of consent, you aren't making a mistake; you're building a feature. The regulator isn't just punishing a privacy breach; they are punishing the attempt to deceive the regulator itself.
The second-order effect here will be felt by the lead generation vendors. For years, these third-party firms have sold "consented" lists to big enterprises with a wink and a nod. Large firms have happily outsourced the ethical headache, assuming that if the vendor provides a certificate of compliance, the risk is transferred.
This fine suggests the regulator is tired of that fiction. The "we bought the leads from a certified provider" defence is rotting. Now, the burden shifts back to the entity actually using the data. If your vendor is spoofing calls to fill your CRM, you aren't a victim of their fraud; you are the beneficiary of it.
Other firms will be watching this closely. South Korea's KT recently took a $39 million hit for a data breach, but that was a failure of security. The TIM fine is a failure of integrity.
The SEC has also been busy with those who struggle with basic housekeeping. Lument Finance Trust, Humacyte, and Mira Pharmaceuticals have all disclosed failures to satisfy continued listing rules. These are different kinds of paperwork failures (the sort where you simply forget to file the right form or miss a financial threshold), but they share a common thread with TIM. They represent a disconnect between how a company thinks it is performing and what the rulebook actually requires.
Even in the world of sport, the paperwork is catching up. Chelsea FC has been hit with a £10 million fine for breaking agent rules. It's another instance where the internal desire to "get the deal done" overrode the regulatory requirement to document it correctly.
The commonality across these sectors is a belief that the rule is a hurdle to be jumped or bypassed, rather than a boundary to be respected.
We see this in the US too, where the City of Wichita is currently being sued over its use of Flock Safety's surveillance cameras. The argument there isn't about whether the technology works (it does), but whether the legal authority to use it as a "warrantless dragnet" actually exists.
The question for any compliance officer this week should be: if the regulator stopped looking at my certificates and started looking at my raw call logs, would I still be compliant?
If the answer depends on your vendor's honesty, you have a problem.