In short
The Italian DPA fined Altroconsumo Edizioni Srl EUR 280,000 (decision of 18 June 2026, doc. web 10269624). Two strands: the use for email marketing of data collected on www.altroconsumo.it, and the delay in responding to data subject rights requests. On this second point the company had already been fined in an earlier decision.
The facts
The proceeding started from a complaint by a citizen who was receiving promotional emails from the publisher without the necessary legal basis, and despite having already asked to stop receiving them. The complainant had never filled in the membership form on the website, and the company was unable to demonstrate the correctness of the contractual relationship it invoked as the ground for sending.
The technical flaw, which is the real reason for the fine
The investigation found that the website registration procedure was not supported by technical and organisational measures suitable to prevent unlawful processing, particularly where registration and the contractual relationship were not completed. Specifically: even when users chose not to confirm account creation — and therefore not to sign up — the company still treated the contract as concluded and proceeded to send promotional emails.
Why this concerns almost every client you have
The pattern is ordinary: a sign-up form, a confirmation email, and a database that writes the record at the first step instead of the second. Nobody does it on purpose. But the result is that the address of whoever changed their mind halfway — the largest share of any sign-up funnel — stays on the list with a "registered user" flag nobody has ever checked.
The questions to put to the client
- At what point is the user record written: on form submission, or on confirmation of the emailed link?
- If confirmation never arrives, what happens to that record after 24 hours, 7 days, 30 days? Is there automatic deletion, or does it just sit there?
- Is the legal basis declared in the record contract or consent? And can the system tell the two populations apart?
- Does a marketing objection raised on one channel propagate to all systems, or only to the one where it was collected?
- How long passes between a rights request and the reply? Is it measured, or discovered when the complaint arrives?
The corrective measures
- Administrative fine of EUR 280,000
- Order to cease processing the data of those who did not confirm the creation of their account
- Order to bring processing procedures into line with the GDPR
The harder order to execute is the second
Ceasing to process those who did not confirm the account presupposes that the company can isolate that population. If the database does not distinguish confirmed from never-confirmed accounts, compliance requires a clean-up before the deletion. That is the kind of work worth doing before an authority is the one asking.
The second strand deserves a note of its own: the failure to adopt measures ensuring the effective exercise of rights and a reply without undue delay. The company had already been fined on this point. A repeat on a procedural obligation — reply within a month — weighs more than most controllers assume, because it shows the first decision produced no organisational change at all.
Official source:Garante privacy - Provvedimento del 18 giugno 2026 [10269624]Official source:Garante privacy - Newsletter n. 550 del 29 luglio 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free