Unauthorised call centres operating on behalf of TIM through sales-network agencies. The agency names are redacted in the published decisionhigh
The callback request you never made: how an unlawful call is made to look lawful
On 31 July 2026 the Italian data protection authority disclosed a fine of EUR 9,516,000 against TIM. At the centre of it is not a systems breach but a mechanism: unauthorised call centres phoned numbers listed on the public opt-out register while spoofing the calling line, then sent a text message with a link to an official partner's web page, and from that form a callback request was generated that the user had never truly made. From that point on the second call came from a properly registered number, and the whole flow looked clean on paper. Around 7,000 complaints in 2025 alone. The authority also found systematic failure to honour data subject rights and unsubscribe procedures that were «excessively complex and, in some cases, not working».
The problem is not the call. It is the second one
Anyone with a phone in Italy knows the first half of this story: an unknown number rings, and someone on the other end pitches a telecoms offer. If the number is on the public opt-out register that call should not arrive, and indeed it often comes from a spoofed line, or from a number not listed on the communications operators register.
That much is the phenomenon everyone knows. The authority's decision of 23 July 2026, made public on 31 July, describes what happens next, and that is the part nobody sees.
After the irregular call, the user receives a text message with a link. The link leads to the web page of an official partner in TIM's sales network: an authorised party, a legitimate site, a real form. On that form the user is invited to enter their details in order to make an «autonomous callback request» — in industry jargon, a Lead.
At that point the call centre rings back. But this second time it uses a number properly listed on the operators register, and it holds a formally valid contact request. The authority puts it precisely: the callback happens «in order to generate an apparently lawful call flow and a formally regular contracting process».
- 01First callspoofed or unregistered number, dialling lines on the opt-out register
- 02Text with linkofficial partner's page, callback request form
- 03Second callregistered number, «Lead» in hand: on paper everything is in order
What an auditor sees
This is where the mechanism becomes interesting from a security standpoint, not only a privacy one. Anyone running a downstream check — the parent company, an auditor, a certification body — finds a tidy chain: an explicit user request, a call placed from a registered number, a contract signed with consent collected.
The defect is in none of the three steps taken individually. It is in the fact that the first step, the unlawful one, leaves no trace in the file. The Lead exists precisely for this: to give a documentable origin to a contact that had a different origin.
The volume gives the scale. The proceeding arose from «numerous complaints and reports concerning unsolicited promotional calls made on behalf of TIM», quantified by the authority at around 7,000 in 2025.
A code of conduct is not a shield
The company's defence rested partly on its adherence to an industry code of conduct. The authority found the justifications insufficient and restated a principle that reaches well beyond telemarketing: adherence to a code of conduct «does not relieve the controller of the obligation to oversee the conduct of its partners and to verify the effective application of data protection measures along the entire telemarketing chain».
It is the same logic found in every supply chain: a certification attests that a process was described and assessed at a point in time, not that it is working right now, at that supplier, on that data flow. Stopping at the certificate means auditing the document, not the activity.
The second finding, the one that touches everyone
Beyond the Lead scheme, the authority established systematic failure to comply with obligations on the exercise of data subject rights: missing or late responses to access, erasure and objection requests, and unsubscribe procedures that were «excessively complex and, in some cases, not working».
This part deserves attention because it is the least spectacular and the most concrete. A right that exists on paper but requires a tortuous path to exercise — or that leads to a broken form — produces the same practical outcome as a right denied. With one difference: nobody notices from outside, because the feature is formally there.
What the company must do, beyond paying
The decision does not end with the fine. TIM must:
- introduce corrective measures in the Lead generation procedure — that is, act on the mechanism that made the scheme possible, not only on individual call centres;
- strengthen controls and oversight of the sales network;
- bring its procedures for the exercise of data subject rights into line.
The order of the three is not accidental: the first is the structural one. Sanctioning unauthorised call centres one at a time is endless work while the channel that turns an unlawful contact into a valid request remains standing.
What to take away
If you get a text with a link after a promotional call, that form is not a formality. Filling it in generates your request to be called back: it is the document that makes the next call lawful. Not filling it in is the most effective thing you can do — far more so than hanging up.
Registering on the public opt-out list still matters, but it is not a technical barrier. It works as a legal obligation on the caller, not as a filter on the network: anyone spoofing the number bypasses it, and it is precisely for that reason that the breach is documentable and punishable. If you receive promotional calls on a registered line, reporting it has concrete value — that is how the 7,000 complaints that opened this proceeding came about.
If you run an outsourced chain, the control point is not the contract: it is the data. The useful question is not «have my partners signed up to the code of conduct», but «where does this contact physically come from, and can I trace it back to its origin?». Here the documentary answer was correct and the real story was something else.
What we do not know
The names of the partner agencies are redacted in the published decision: it is not possible to reconstruct publicly which parties actually operated. It is not known whether the company opted for the reduced settlement provided by Article 166(8) of the Italian Privacy Code — which allows closure by paying half the fine within thirty days — nor whether it filed an appeal. The figure of around 7,000 complaints refers to reports received in 2025 concerning TIM, and should not be read as a measure of unlawful telemarketing in Italy as a whole, which is broader and involves many operators.