Enforcement decisions by the Italian Data Protection Authority (Garante)medium
Debt collection: Italy's DPA fines twice — the company that outsources and the one that executes
A debtor reports that, in order to reach him, a debt collection firm used a mobile number registered in his name but no longer in his possession — and asks where it came from. From that single complaint the Italian DPA reaches two fines: EUR 50,000 for the company acting as controller and EUR 30,000 for the collection firm acting as processor. The message is the most important one the GDPR contains about outsourcing: delegating the work does not delegate the duty, and oversight of a vendor must be periodic, documented and verifiable.
A simple question, and no answer
The case starts with a complaint that is anything but exotic. A person is contacted as part of a debt collection effort on a mobile number registered in his name but no longer in his possession. He objects to how his data was handled and asks the question anyone would ask: where did you get this number?
The Italian Data Protection Authority opens an investigation and closes it with two enforcement decisions: EUR 50,000 for the company acting as data controller and EUR 30,000 for the debt collection firm, the recipient of the debtor's data transmitted by the controller, acting as data processor.
Two fines from one complaint. That detail is where the whole reasoning starts.
Why two, and not one
Under the GDPR the controller determines the purposes and means of processing; the processor processes data on the controller's behalf, under a contract and documented instructions (that is Article 28). When a company outsources the collection of its receivables, that firm does not become the owner of the data: it processes it on behalf of whoever handed it over, inside a defined perimeter.
The point — and here the decision is very clear — is that the perimeter does not police itself.
- 01The controllermust run periodic, documented and verifiable checks on the outsourced activity
- 02The processormust put in place measures giving the controller an exact, up-to-date picture of the data processed
- 03The debtorasks a question, and the system has to be able to answer
The investigation found that the controller had not adequately supervised the processor's activity nor the instructions given to it. And that the processor had not given the controller an updated picture of the information collected during the engagement, nor informed it that the debtor had asked where the contacted number came from.
Put differently: the controller was not looking, the processor was not telling. Neither of them, taken alone, had committed a spectacular abuse. Together they had built a system in which a legitimate question could not be answered.
The sentence that works as a rule
The Authority's wording deserves to be read as an operational rule, because it was written to be one.
In debt collection activities the controller must carry out periodic, documented and verifiable checks to monitor, from a data protection standpoint, the activities entrusted to third-party processors. Those processors, in turn, must adopt technical and organisational measures giving the controller an exact and up-to-date picture of the information actually collected and processed to manage the debtor's position.
The three words that make the difference are periodic, documented and verifiable. Not "once a year if we get round to it", not "we trust the vendor", not "there's a clause in the contract". A check that leaves no trace is, in GDPR terms, a check that did not happen: the accountability principle asks you to demonstrate compliance, not to assert it.
What to take away, if you manage vendors
This decision is not only about debt collection. It concerns anyone who outsources the processing of personal data — a call centre, a logistics firm, an IT service provider, a marketing agency.
The questions to ask are few and uncomfortable. When did you last verify what your vendor actually processes, as opposed to what the contract says it should? Is there a document somewhere recording that verification, with a date on it? If a data subject asked you tomorrow where a piece of their data held by the vendor came from, could you answer within a reasonable time, or would you have to ask the vendor and hope it knows? And does your contract require the vendor to inform you of the requests it receives from data subjects, or does it let the vendor handle them alone without telling you anything?
In setting the amounts, the Authority took into account both the seriousness of the violations and the steps the two companies had taken to prevent similar situations from recurring: remedial measures count, and they count more when they arrive before the fine.
One necessary note
The two decisions were made public in the Garante's newsletter of 16 July 2026, which does not publicly name the companies involved: this dossier reports the roles and the amounts as published by the Authority, with no further attribution. Anyone wanting the full reasoning will find the two documents linked at the top of the page. And it is worth remembering that a fine imposed on the processor does not reduce the one imposed on the controller: under the GDPR the two responsibilities are independent, and this case is the pocket-sized proof.