[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgj8FLF2HOHdS_Sbr8a1tK0tUHUXlN1wHK7nSSuuYk0s":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"9d85a2cc-9b34-46de-acc1-511ebd67501c","italian-publisher-fined-280k-for-marketing-emails-sent-without-valid-gdpr-consent","65fcbd5d-1fb5-4cd7-aee1-5886d03687b2","Italian Publisher Fined €280K for Marketing Emails Sent Without Valid GDPR Consent","The publishing company processed personal data for marketing purposes without a lawful basis, sending promotional emails and making calls to a user who never confirmed their account registration. This violates the GDPR's core principle that processing must have a valid legal ground — such as explicit consent or a legitimate contract — before any communication occurs. The company compounded the violation by ignoring the data subject's right to object and failing to cooperate with the Garante during the investigation. This case illustrates that automated marketing pipelines must have consent verification gates built in, not treated as optional steps. Repeat infringements and non-cooperation significantly increase regulatory penalties, making a culture of compliance essential.","**Immediate actions:**\n- Implement a confirmed opt-in (double opt-in) mechanism that blocks all marketing communications until the user verifies their email address.\n- Audit all active marketing lists to remove contacts who have not completed a valid consent or contractual confirmation process.\n- Establish a documented process for honoring right-to-object and unsubscribe requests within the legally required timeframe.\n\n**Long-term improvements:**\n- Build consent management platforms (CMPs) that record the timestamp, version, and method of consent for every data subject.\n- Conduct annual GDPR compliance reviews of all marketing workflows, including third-party tools and CRM integrations.\n- Train marketing and sales teams on lawful basis requirements under GDPR Articles 6 and 7 to ensure operational staff understand their legal obligations.\n\n**Detection & Response measures:**\n- Deploy logging and monitoring on marketing automation systems to detect and alert on communications sent to unverified or opted-out contacts.\n- Assign a designated Data Protection Officer (DPO) point of contact for regulatory inquiries to ensure timely and cooperative responses to DPA investigations.\n- Establish an internal escalation procedure for data subject complaints so violations are identified and remediated before they reach regulatory bodies.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness, and transparency","GDPR Article 6 – Lawfulness of processing","GDPR Article 7 – Conditions for consent","GDPR Article 21 – Right to object","GDPR Article 83 – General conditions for imposing administrative fines","NIST SP 800-53 PT-3 – Personally Identifiable Information Processing Purposes","NIST SP 800-53 PT-5 – Privacy Notice","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management","ITIL Service Design – Data governance and compliance management","published","2026-08-20T14:22:13.979942+00:00","2026-08-20T14:22:13.691+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10269624&diff=52741&oldid=52740","garante-per-la-protezione-dei-dati-personali-italy-10269624-173332","Garante per la protezione dei dati personali (Italy) - 10269624",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]