What the Garante actually decided
Italy's data protection authority, the Garante, fined TIM €9,516,000 in a decision dated 23 July 2026 and publicised on 31 July. It found that call centres working on TIM's behalf used numbers outside the official sales network, some spoofed, to collect personal data from people who believed they were speaking to an authorised agent. Roughly 7,000 complaints arrived in 2025, many from numbers listed in the Public Register of Objections. The regulator also found systematic failures to answer access, deletion and objection requests, or to answer them on time, plus unsubscribe procedures that were overly complex or did not work (Garante decision; DIMT summary).
One caveat up front. This is a telemarketing and data-subject-rights case. The decision I reviewed says nothing about law-enforcement requests, and I found no verified Italian law-enforcement data-request event in the past 60 days. Any link to that topic is analytical, not factual.
The strongest case for the fine
The case for a heavy penalty is strong. Telemarketing fraud that impersonates a carrier erodes trust in the whole communications sector. A firm that cannot reliably process a deletion request has, in practice, no working rights regime. The Garante also rejected a defence many firms rely on: adherence to a code of conduct does not relieve a controller of the duty to supervise its partners. Fines that do not bite are simply a cost of doing business, and a consumer facing 7,000 unwanted calls has little leverage without them.
I agree with most of this. The finding is proportionate because it targets identifiable conduct: spoofed calls, ignored requests and weak partner oversight. It does not punish telemarketing itself. The ordered remedies are also constructive: TIM must revise its lead-generation process, strengthen sales-network controls and fix the channel through which users exercise their rights. That is what proportionate, evidence-based enforcement looks like, and it leaves room for legitimate marketing and innovation.
Why a carrier's rights-handling matters for law enforcement
Telecom operators sit at a pressure point. The same firms answering consumer complaints also hold call and traffic records that prosecutors want. The Garante's decision does not touch that, so the connection is structural. If a carrier's rights-request handling is unreliable, there is little reason to assume its handling of the far more sensitive records demanded by the state is flawless.
Italy has a long, documented dispute over those records. In a July 2021 report to Parliament and the Government, the Garante urged reform of Article 132 of the Privacy Code. It described a framework that allowed traffic-data retention for 24 months, extendable to 72 months for serious crimes, and it argued this conflicted with EU law. It stressed that access should be subject to prior review by a judge or independent authority, not only prosecutorial decree (Garante report, 2021). That report relied on Court of Justice case law, including Digital Rights Ireland (2014) and Tele2 Sverige (2016), which rejected generalised and indiscriminate retention. I have not verified how Italian law has changed since, so the 2021 description should be treated as historical.
Where the law-enforcement debate should learn from this
The steelman for broad retention is real. Investigators in organised-crime and terrorism cases often need historical records, and records not kept cannot be recovered. But the Court of Justice has held that even access to limited traffic data is a serious interference with fundamental rights, justified only by serious crime or serious threats to public security. A necessity test that is narrow and targeted also keeps data-holding costs down for carriers.
The TIM decision suggests three principles that carry over:
- Deadlines are enforceable. Late or missing answers to rights requests drew a fine. Any request channel, including one handling official demands, should have logged, auditable response times.
- Supervision cannot be delegated. A carrier is responsible for its partners. The same logic implies clear internal separation and accountability for teams that release records to authorities.
- Transparency is the check. Oversight is weakest where use is hidden. EFF's September 2026 reporting on US police concealing surveillance tools, including instructions to be "as vague as permissible" about them, is a reminder that secrecy defeats accountability. It describes a different legal system, so it is a caution and not a parallel (EFF).
A proportionate path
Italy does not need a new surveillance-limiting statute because of one telemarketing fine. It does need consistent application of what already exists. Carriers should publish aggregate statistics on judicial data requests received and fulfilled. Access should sit behind independent authorisation. Retention should be tied to crime severity, as the Garante itself proposed. None of this hampers legitimate investigations, and it preserves the trust that lets a communications market grow.
The TIM case shows the Garante will hold a large operator to the basics. The open question is whether that same rigor reaches the records that matter most to citizens' liberty.