Back to Feed
PolicyAug 20, 2026

Garante per la protezione dei dati personali (Italy) - 10269624

Italian DPA fines a publisher €280,000 for unlawful marketing emails and data processing.

Summary

Italy's Garante has fined a publishing company €280,000 for sending marketing emails without valid consent or a contract. The data subject never confirmed their account, but the company proceeded with sending promotional emails and making calls. The DPA found violations of GDPR articles related to lawful processing, consent, and the right to object, also noting the company's lack of cooperation and previous infringements.

Full text

Help Garante per la protezione dei dati personali (Italy) - 10269624: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 11:50, 20 August 2026 view sourceLigialagev (talk | contribs)40 edits Tag: Decisions [1.0] Latest revision as of 12:00, 20 August 2026 view source Ligialagev (talk | contribs)40 editsm Tag: Visual edit Line 105: Line 105: === Facts ====== Facts === The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the site, ticking a box acknowledging the privacy policy and accepting the General Terms. The controller then sends an email asking the user to click a link to confirm their account and complete the registration. Under the controller's General Terms, a user who registers through the form becomes a "FAN" and thereby enters into a contractual relationship with the controller. On that basis, the controller sends such users around 16 to 20 commercial emails per month.The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the site, ticking a box acknowledging the privacy policy and accepting the General Terms. The controller then sends an email asking the user to click a link to confirm their account and complete the registration. The data subject started receiving promotional emails from the controller, and was also called by the controller's processor, who offered them a subscription. The data subject denied ever having visited the controller's website or having filled in the registration form. The controller, on the other hand, stated that its logs recorded three visits attributable to the data subject: two on 11 August 2025 and one on 5 September 2025, during which the form was completed. In the file submitted as evidence, the data subject's surname was misspelt on all three occasions and the three connections came from Canadian IP addresses. The data subject's email address was therefore the only element directly linking those visits to them. The data subject never confirmed the account. The controller sent three unanswered confirmation emails and then began sending promotional emails anyway, as if the registration had been completed.The data subject started receiving promotional emails from the controller, and was also called by the controller's processor, who offered them a subscription. The data subject denied ever having visited the controller's website or having filled in the registration form. The controller, on the other hand, stated that its logs recorded three visits attributable to the data subject: two on 11 August 2025 and one on 5 September 2025, during which the form was completed. In the file submitted as evidence, the data subject's surname was misspelt on all three occasions and the three connections came from Canadian IP addresses. The controller sent three unanswered confirmation emails and then began sending promotional emails anyway, as if the registration had been completed. On 17 September 2025, the data subject sent the processor a form exercising their right of access and their right to object to processing for direct marketing purposes. The processor forwarded it to the controller the same day. As the promotional emails continued, the data subject sent the same form directly to the controller on 11 October 2025. The last promotional email on record was sent on 3 November 2025.On 17 September 2025, the data subject sent the processor a form exercising their right of access and their right to object to processing for direct marketing purposes. The processor forwarded it to the controller the same day. As the promotional emails continued, the data subject sent the same form directly to the controller on 11 October 2025. The last promotional email was sent on 3 November 2025. On 4 November 2025, the data subject lodged a complaint with the DPA. On 9 February 2026, the DPA asked the controller for information under Article 157 of the Italian Data Protection Code. The controller did not reply. On 31 March 2026, the DPA opened proceedings.On 4 November 2025, the data subject lodged a complaint with the DPA. On 9 February 2026, the DPA asked the controller for information under Article 157 of the Italian Data Protection Code, which went unanswered. On 31 March 2026, the DPA opened proceedings. In its defence of 5 May 2026, the controller argued that it had failed to reply because of a handover between its former internal DPO and a new external one as of 1 January 2026. On the merits, it argued that the contractual relationship had been validly established through the form, and that account confirmation was a merely technical step in activating the account rather than a double opt-in mechanism. It also argued that it had complied with the objection within 30 days of 11 October 2025, and that the misspelt surname had delayed processing the request. The controller requested a hearing and then withdrew the request on 8 May 2026.In its defence of 5 May 2026, the controller argued that it had failed to reply because of a handover between its former internal DPO and a new external one as of 1 January 2026. On the merits, it argued that the contractual relationship had been validly established through the form, and that account confirmation was a merely technical step in activating the account rather than a double opt-in mechanism. It also argued that it had complied with the objection within 30 days of 11 October 2025, and that the misspelt surname had delayed processing the request. The controller requested a hearing and then withdrew the request on 8 May 2026. Line 125: Line 125: Fourth, since no contract had been established, the DPA held that the email address had not been obtained in the context of the sale of similar goods or services, so the soft spam exemption in Article 130(4) of the Codice did not apply. The DPA further noted that the sign-up form only contained a tick box acknowledging the privacy policy, which meant the controller collected no marketing consent under Article 130(2) of the Codice. Therefore, the DPA found a violation of Articles 6 and 7 GDPR and Article 130 of the Codice.Fourth, since no contract had been established, the DPA held that the email address had not been obtained in the context of the sale of similar goods or services, so the soft spam exemption in Article 130(4) of the Codice did not apply. The DPA further noted that the sign-up form only contained a tick box acknowledging the privacy policy, which meant the controller collected no marketing consent under Article 130(2) of the Codice. Therefore, the DPA found a violation of Articles 6 and 7 GDPR and Article 130 of the Codice. Fifth, the DPA held that the objection had been validly exercised on 17 September 2025, when the processor received it and informed the controller the same day. Requiring the data subject to repeat the request to the controller would add a burden not provided for by the GDPR, especially given the processor's duty to assist the controller under [[Article 28 GDPR|Article 28(3)(e) GDPR]]. The time limit under [[Article 12 GDPR|Article 12(3) GDPR]] therefore expired on 17 October 2025, while the controller only stopped sending emails after 3 November 2025. The DPA rejected the argument about the misspelt surname, as the processor had had no difficulty identifying the data subject. Therefore, the DPA found a violation of [[Article 21 GDPR|Article 21 GDPR]].Fifth, the DPA held that the objection had been validly exercised on 17 September 2025, when the processor received it and informed the controller the same day. Requiring the data subject to repeat the request to the controller would add a burden not provided for by the GDPR, especially given the processor's duty to assist the controller under [[Article 28 GDPR|Article 28(3)(e) GDPR]

Entities

Garante per la protezione dei dati personali (vendor)GDPR (product)