The Italian authority sanctions Altroconsumo Edizioni for sending unsolicited commercial communications

The Italian supervisory authority (Garante) sanctioned a company for sending commercial communications without a valid legal basis, wrongly considering that a contract was formed upon submission of an online form, without waiting for the user's email address confirmation.

Facts and context

The Italian supervisory authority (Garante per la protezione dei dati personali, GPDP) has today published a sanction decision against Altroconsumo Edizioni s.r.l. (including the imposition of a fine of €280,000) for breaches related to the legal basis of processing, commercial prospecting, and respect for the right to object.

The case originated from a complaint by a person who received unsolicited commercial communications, while denying having registered and whose objection request remained ineffective.

Reasons for the decision

  • Obligation to have a legal basis for processing (Article 6 of the GDPR): The company argued that a contractual relationship arose as soon as the user submitted the online form, justifying processing based on the performance of pre-contractual measures. The authority rejected this argument, noting that the registration process itself required clicking on a confirmation link sent by email to be completed. Without this confirmation, which resembles a double opt-in mechanism, no contractual relationship can be considered validly formed. Furthermore, the evidence provided by the company (a spreadsheet file of connection logs) was deemed insufficient to guarantee their integrity and immutability, especially since the complainant denied any registration and the connection data showed anomalies (Canadian IP addresses, misspelled last name).
  • Obligation to obtain consent for electronic prospecting (Articles 6 and 7 of the GDPR and Article 130 of the Italian Data Protection Code): In the absence of a proven contractual relationship, the company could not rely on the so-called "existing customer" exception (soft opt-in) to send commercial communications. The authority also found that the registration form did not include any checkbox to collect specific consent for prospecting. Consequently, the sending of promotional emails lacked any legal basis.
  • Obligation to respect the right to object (Article 21 of the GDPR): The complainant exercised their right to object on 17 September 2025 via a processor, who informed the controller the same day. The company only stopped sending after 3 November 2025, well beyond the one-month deadline. The authority considered that the deadline started from 17 September, the date on which the company became aware of the request, and not from a later reminder by the complainant. The identification difficulties invoked by the company due to a misspelling of the last name were deemed irrelevant.
  • Obligation to cooperate with the authority (Article 157 of the Italian Data Protection Code): The company did not respond to a request for information from the authority. It justified its silence by a change of data protection officer. The authority considered that internal organizational difficulties cannot constitute an objective impediment and do not exempt the controller from its obligation to cooperate, which would have at least required informing the authority of the difficulties encountered.

Authority's decision

Consequently, the authority imposed a fine of €280,000 on Altroconsumo Edizioni s.r.l.

Furthermore, the authority ordered the company to bring its processing into compliance, notably by relying on the contractual legal basis only if the user has actually confirmed their account, and to adopt measures to facilitate the exercise of data subjects' rights and respond without undue delay.

Lessons learned

This decision confirms that:

  • A registration process requiring email confirmation to be finalized must be considered a double opt-in mechanism; without this confirmation, no contractual relationship is formed.
  • Proof of the existence of a contractual relationship or online registration must be based on technical elements providing guarantees of integrity and immutability, a simple spreadsheet file being deemed insufficient.
  • The deadline to respond to an objection request starts from the moment the controller becomes aware of it, even if the request was initially addressed to a processor who then forwarded it.
  • Internal organizational difficulties, such as a change of data protection officer, do not constitute a legitimate reason for failing to respond to a supervisory authority's request for information.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire