Codice Privacy (Personal Data Protection Code), Article 130(1), (2) and (4) to (6), Unsolicited Communications
Decreto legislativo 30 giugno 2003, n. 196, art. 130(1), (2), (4)-(6)
In force since .
A commercial messages rule binding public and private bodies.
- Obligation class
- Consent, Disclosure, Prohibition
As of .
What it requires
- Obtain the consent of the subscriber or user before sending advertising or direct-sale material, market research or commercial communication by an automated calling or communication system without an operator, or by email, fax, MMS, SMS or another type of electronic message.
- If you use for direct sale of your own products or services the email contact details that a data subject gave you in the context of a sale of a product or service, you may do so without consent only for services similar to those sold and if the data subject, adequately informed, does not refuse that use, initially or on later communications. Tell the data subject at collection, and in every communication sent on that basis, that they can object at any time, easily and free of charge.
- Do not send such communications, or any communication for promotional purposes, while disguising or concealing the sender's identity, in breach of Article 8 of Legislative Decree 70/2003, without giving a suitable contact where the data subject can exercise the rights in Articles 15 to 22 of the General Data Protection Regulation (GDPR), or by urging recipients to visit websites that breach that Article 8.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 167(1) punishes with imprisonment of six months to one year and six months anyone who, to obtain a profit for themselves or others or to cause harm to the data subject, acts in breach of Article 123, 126 or 130 and thereby causes harm to the data subject, unless the act is a more serious offense.
Penalty structure
Article 166(2) places violations of Article 130, paragraphs 1 to 5, under the administrative sanction of Article 83(5) of the GDPR, which sets fines of up to EUR 20,000,000 or, for an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
The Garante per la protezione dei dati personali, which Article 166(3) makes competent to adopt corrective measures and to impose the sanctions of Article 83 of the GDPR.
What this law does
Article 130(1) permits the use of automated calling or communication systems without the intervention of an operator to send advertising or direct-sale material, for market research or for commercial communication, with the consent of the subscriber or user. Article 130(2) applies that provision also to electronic communications sent for those purposes by email, fax, MMS or SMS messages or messages of another type.
Article 121(1-bis)(f) defines a subscriber (contraente) as any natural person, legal person, body or association party to a contract with a provider of publicly available electronic communications services for their supply, or otherwise the recipient of such services through prepaid cards.
Article 130(4) provides that a controller that uses, for direct sale of its own products or services, the email contact details the data subject gave in the context of the sale of a product or service may dispense with consent, provided the services are similar to those sold and the data subject, adequately informed, does not refuse that use, initially or on later communications.
The data subject must be informed, at collection and at every communication sent under that paragraph, of the possibility of objecting at any time, easily and free of charge.
Article 130(5) prohibits in every case sending communications for the purposes of paragraph 1, or otherwise for promotion, by disguising or concealing the sender's identity, in breach of Article 8 of Legislative Decree 70/2003, without a suitable contact where the data subject can exercise the rights in Articles 15 to 22 of the General Data Protection Regulation (GDPR), or by urging recipients to visit websites that breach that Article 8.
Under Article 130(6), in case of repeated violation the Garante may also prescribe to electronic communications service providers filtering procedures or other practicable measures for the email addresses from which the communications were sent. Article 166(2) places violations of Article 130, paragraphs 1 to 5, under the administrative sanction of Article 83(5) of the GDPR.
Article 83(5) of the GDPR sets fines of up to EUR 20,000,000 or, for an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.
Article 167(1) punishes with imprisonment of six months to one year and six months anyone who, to obtain a profit for themselves or others or to cause harm to the data subject, acts in breach of Article 123, 126 or 130 or of the Garante's measure under Article 129 and thereby causes harm to the data subject, unless the act is a more serious offense.
When LexLint raises it
When your app profile says your app sends automated outreach.