Garante per la protezione dei dati personali (Italy) - 10269624
Italy's Garante fines publisher €280,000 for sending marketing emails without confirmed sign-up.
Summary
Italy's Garante per la protezione dei dati personali has fined Altroconsumo Edizioni S.r.l. €280,000 for sending marketing emails to a user who never confirmed their account registration. The publisher argued a contract was formed upon form submission, but the Garante found no confirmation meant no contractual basis under GDPR Article 6(1)(b). The user also denied ever visiting the site, and the controller failed to respond to the DPA's inquiries.
Full text
Help Garante per la protezione dei dati personali (Italy) - 10269624: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 11:50, 20 August 2026 view source Ligialagev (talk | contribs)40 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 11:50, 20 August 2026 Garante per la protezione dei dati personali - 10269624 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 6(1)(b) GDPR Article 7 GDPR Article 12(3) GDPR Article 21(2) GDPR Article 28(3)(e) GDPR Type: Complaint Outcome: Upheld Started: Decided: Published: 18.06.2026 Fine: 280000.0 EUR Parties: Altroconsumo Edizioni S.r.l. National Case Number/Name: 10269624 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: ligialagev The DPA fined a controller €280,000 for sending marketing emails to a user who had never confirmed their sign-up. Without that confirmation, no contract existed and Article 6(1)(b) GDPR could not apply. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the site, ticking a box acknowledging the privacy policy and accepting the General Terms. The controller then sends an email asking the user to click a link to confirm their account and complete the registration. Under the controller's General Terms, a user who registers through the form becomes a "FAN" and thereby enters into a contractual relationship with the controller. On that basis, the controller sends such users around 16 to 20 commercial emails per month. The data subject started receiving promotional emails from the controller, and was also called by the controller's processor, who offered them a subscription. The data subject denied ever having visited the controller's website or having filled in the registration form. The controller, on the other hand, stated that its logs recorded three visits attributable to the data subject: two on 11 August 2025 and one on 5 September 2025, during which the form was completed. In the file submitted as evidence, the data subject's surname was misspelt on all three occasions and the three connections came from Canadian IP addresses. The data subject's email address was therefore the only element directly linking those visits to them. The data subject never confirmed the account. The controller sent three unanswered confirmation emails and then began sending promotional emails anyway, as if the registration had been completed. On 17 September 2025, the data subject sent the processor a form exercising their right of access and their right to object to processing for direct marketing purposes. The processor forwarded it to the controller the same day. As the promotional emails continued, the data subject sent the same form directly to the controller on 11 October 2025. The last promotional email on record was sent on 3 November 2025. On 4 November 2025, the data subject lodged a complaint with the DPA. On 9 February 2026, the DPA asked the controller for information under Article 157 of the Italian Data Protection Code. The controller did not reply. On 31 March 2026, the DPA opened proceedings. In its defence of 5 May 2026, the controller argued that it had failed to reply because of a handover between its former internal DPO and a new external one as of 1 January 2026. On the merits, it argued that the contractual relationship had been validly established through the form, and that account confirmation was a merely technical step in activating the account rather than a double opt-in mechanism. It also argued that it had complied with the objection within 30 days of 11 October 2025, and that the misspelt surname had delayed processing the request. The controller requested a hearing and then withdrew the request on 8 May 2026. Holding First, the DPA held that a DPO handover was neither an unforeseeable event nor force majeure. A controller genuinely willing to cooperate would have flagged the difficulty to the DPA in good time and asked for an extension, instead of raising it only after proceedings had been opened. Therefore, the DPA found a violation of Article 157 of the Codice. Second, the DPA held that the controller had not proven the contractual relationship it relied on. The Excel file submitted as evidence of the website visits offered no guarantee of integrity or immutability, which the DPA considers necessary where the data subject denies having filled in the form at all. The DPA also noted that the surname was wrong three times over and that the IP addresses were Canadian, so that the email address was the only element linking the visits to the data subject. Third, the DPA held that account confirmation was a double opt-in mechanism, not a technical formality. The controller's own General Terms defined a "FAN" as a consumer who establishes a contractual relationship by registering through the form, and its first email told users that one click was still missing to complete their registration. Where the account was never confirmed, the registration remained incomplete and no contract came into existence. The DPA added that, once three unanswered confirmation emails had been sent, passing the data to the processor for a phone call could not qualify as a pre-contractual measure taken at the data subject's request. Therefore, the DPA found that the controller could not rely on Article 6(1)(b) GDPR and held the processing unlawful. Fourth, since no contract had been established, the DPA held that the email address had not been obtained in the context of the sale of similar goods or services, so the soft spam exemption in Article 130(4) of the Codice did not apply. The DPA further noted that the sign-up form only contained a tick box acknowledging the privacy policy, which meant the controller collected no marketing consent under Article 130(2) of the Codice. Therefore, the DPA found a violation of Articles 6 and 7 GDPR and Article 130 of the Codice. Fifth, the DPA held that the objection had been validly exercised on 17 September 2025, when the processor received it and informed the controller the same day. Requiring the data subject to repeat the request to the controller would add a burden not provided for by the GDPR, especially given the processor's duty to assist the controller under Article 28(3)(e) GDPR. The time limit under Article 12(3) GDPR therefore expired on 17 October 2025, while the controller only stopped sending emails after 3 November 2025. The DPA rejected the argument about the misspelt surname, as the processor had had no difficulty identifying the data subject. Therefore, the DPA found a violation of Article 21 GDPR. The DPA classified both sets of violations as medium in severity. As aggravating circumstances, it took into account two previous decisions against the same controller (no. 429 of 15 December 2022 and no. 823 of 19 December 2024, the latter concerning the same violation of Article 21 GDPR) and the complete absence of cooperation during the investigation. It set the fine at €180,000 for the violations of Articles 6, 7 and 21 GDPR and Article 130 of the Codice, and at €100,000 for the violation of Article 157 of the Codice, amounting to €280,000 in total. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to rely on Article 6(1)(b) GDPR only where the user has confirmed their account and to stop processing the data of those who have not, to put in place technical and organisational measures facilitating the exercise of data subject rights, and to report back on the steps taken within 30 days. Comment Share your comments he