Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) ·10269624 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Garante · 10269624

The controller is a publishing company that sells subscriptions to consumer information services through its website.

Holding

First, the DPA held that a DPO handover was neither an unforeseeable event nor force majeure. A controller genuinely willing to cooperate would have flagged the difficulty to the DPA in good time and asked for an extension, instead of raising it only after proceedings had been opened. Therefore, the DPA found a violation of Article 157 of the Codice. Second, the DPA held that the controller had not proven the contractual relationship it relied on. The Excel file submitted as evidence of the website visits offered no guarantee of integrity or immutability, which the DPA considers necessary where the data subject denies having filled in the form at all. The DPA also noted that the surname was wrong three times over and that the IP addresses were Canadian, so that the email address was the only element linking the visits to the data subject. Third, the DPA held that account confirmation was a double opt-in mechanism, not a technical formality. The controller's own General Terms defined a "FAN" as a consumer who establishes a contractual relationship by registering through the form, and its first email told users that one click was still missing to complete their registration. Where the account was never confirmed, the registration remained incomplete and no contract came into existence. The DPA added that, once three unanswered confirmation emails had been sent, passing the data to the processor for a phone call could not qualify as a pre-contractual measure taken at the data subject's request. Therefore, the DPA found that the controller could not rely on Article 6(1)(b) GDPR and held the processing unlawful. Fourth, since no contract had been established, the DPA held that the email address had not been obtained in the context of the sale of similar goods or services, so the soft spam exemption in Article 130(4) of the Codice did not apply. The DPA further noted that the sign-up form only contained a tick box acknowledging the privacy policy, which meant the controller collected no marketing consent under Article 130(2) of the Codice. Therefore, the DPA found a violation of Articles 6 and 7 GDPR and Article 130 of the Codice. Fifth, the DPA held that the objection had been validly exercised on 17 September 2025, when the processor received it and informed the controller the same day. Requiring the data subject to repeat the request to the controller would add a burden not provided for by the GDPR, especially given the processor's duty to assist the controller under Article 28(3)(e) GDPR. The time limit under Article 12(3) GDPR therefore expired on 17 October 2025, while the controller only stopped sending emails after 3 November 2025. The DPA rejected the argument about the misspelt surname, as the processor had had no difficulty identifying the data subject. Therefore, the DPA found a violation of Article 21 GDPR. The DPA classified both sets of violations as medium in severity. As aggravating circumstances, it took into account two previous decisions against the same controller (no. 429 of 15 December 2022 and no. 823 of 19 December 2024, the latter concerning the same violation of Article 21 GDPR) and the complete absence of cooperation during the investigation. It set the fine at €180,000 for the violations of Articles 6, 7 and 21 GDPR and Article 130 of the Codice, and at €100,000 for the violation of Article 157 of the Codice, amounting to €280,000 in total. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to rely on Article 6(1)(b) GDPR only where the user has confirmed their account and to stop processing the data of those who have not, to put in place technical and organisational measures facilitating the exercise of data subject rights, and to report back on the steps taken within 30 days.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

Users can sign up by filling in a registration form on the site, ticking a box acknowledging the privacy policy and accepting the General Terms. The controller then sends an email asking the user to click a link to confirm their account and complete the registration. The data subject started receiving promotional emails from the controller, and was also called by the controller's processor, who offered them a subscription. The data subject denied ever having visited the controller's website or having filled in the registration form. The controller, on the other hand, stated that its logs recorded three visits attributable to the data subject: two on 11 August 2025 and one on 5 September 2025, during which the form was completed. In the file submitted as evidence, the data subject's surname was misspelt on all three occasions and the three connections came from Canadian IP addresses. The controller sent three unanswered confirmation emails and then began sending promotional emails anyway, as if the registration had been completed. On 17 September 2025, the data subject sent the processor a form exercising their right of access and their right to object to processing for direct marketing purposes. The processor forwarded it to the controller the same day. As the promotional emails continued, the data subject sent the same form directly to the controller on 11 October 2025. The last promotional email was sent on 3 November 2025. On 4 November 2025, the data subject lodged a complaint with the DPA. On 9 February 2026, the DPA asked the controller for information under Article 157 of the Italian Data Protection Code, which went unanswered. On 31 March 2026, the DPA opened proceedings. In its defence of 5 May 2026, the controller argued that it had failed to reply because of a handover between its former internal DPO and a new external one as of 1 January 2026. On the merits, it argued that the contractual relationship had been validly established through the form, and that account confirmation was a merely technical step in activating the account rather than a double opt-in mechanism. It also argued that it had complied with the objection within 30 days of 11 October 2025, and that the misspelt surname had delayed processing the request. The controller requested a hearing and then withdrew the request on 8 May 2026.

Full text 16 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

SEE ALSO Newsletter of July 29, 2026 [Web Doc. No. 10269624] Decision of June 18, 2026 Register of Decisions No. 464 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on the Protection of Personal Data (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Article 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801); RAPPORTEUR: Prof. Ginevra Cerrina Feroni;

FACTS AND COURSE OF THE PRELIMINARY

¶1

INVESTIGATION

¶1.1

Origin of the preliminary investigation By letter dated November 4, 2025, filed on the same date (Ref. No. 146057), a complaint was received by this Authority alleging that the complainant had received unsolicited commercial communications via email from Altroconsumo Edizioni s.r.l., VAT No. 12581280158, located at Viale Piero e Alberto Pirelli, 10 - 20126 Milan (“Company”), in its capacity as the controller for personal data processed through the website www.altroconsumo.it. On the merits, the complainant denied ever having submitted any request via the Company’s online form and, in any case, never confirmed “his account” to complete the registration process with Altroconsumo. Furthermore, having received numerous communications from the Company, the complainant also exercised his right to object to the processing (in letters dated September 17, 2025, and October 11, 2025); however, he stated that he subsequently received additional promotional emails.

¶1.2

Actions Taken In a letter dated February 9, 2026 (Ref. No. 18848), the Office of the Data Protection Authority issued, pursuant to Article 157 of the Code, a request for information to the Company regarding the matters set forth in the aforementioned complaint. The request, which was duly delivered via certified email (PEC) on the same date, remained unanswered.

INITIATION OF PROCEEDINGS FOR THE ADOPTION

¶2

OF CORRECTIVE AND SANCTIONARY MEASURES AND THE PARTY’S DEFENSES

¶2.1

Initiation of proceedings (Article 166, paragraph 5, of the Code) Based on the above information and the evidence attached to the complaint, by a notice dated March 31, 2026 (Ref. No. 50043), served in accordance with Article 166, paragraph 5, of the Code, the Office initiated proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation against the controller, inviting the controller to submit written defenses or documents to the Data Protection Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). The alleged violations in question concerned the following provisions: - Article 6, para. 1, subparagraph b) of the Regulation, in that the processing carried out by the Company—in connection with communications sent after the first email and in connection with the telephone contact by the processor—does not fall within the scope of pre-contractual measures taken at the request of the data subject; - Articles 6 and 7 of the Regulation and Article 130 of the Code, in that the Company processed the complainant’s personal data for marketing purposes without any appropriate legal basis; - Article 21 of the Regulation, in that the Company did not properly comply with the right to object exercised by the complainant; - Article 157 of the Code, in that the Company did not provide the information requested by the investigating authority.

¶2.2

Defenses of the Party (Article 166, paragraph 6, of the Code) The Company submitted written defenses regarding the proceedings against it and, after requesting a hearing before the Authority and having a date set for it, subsequently waived that right. Specifically, in a brief dated May 5, 2026 (Ref. No. 68431), the controller provided a general overview of the factual circumstances characterizing the case at hand, stating that it had processed the complainant’s personal data (including for marketing purposes) following visits by the complainant himself to the website www.altroconsumo.it. Regarding the allegations raised by the investigating authority, the Company asserted, first, that the failure to respond to requests for information was due to the handover between the previous (in-house) DPO and the new external professional appointed, effective January 1, 2026, to perform that role. According to the Company, this situation prevented it from providing the requested response “without any intention of evading its obligations to cooperate with the Authority.” The Company also argued that the pre-contractual/contractual relationship with the complainant had been properly established, even in the absence of account confirmation by the User, and that, therefore, the processing aimed at finalizing the purchase of a subscription to its services could legitimately be based on Art. 6(1)(b) of the Regulation. In support of this argument, the Company cited its General Terms and Conditions regarding the definitions of “member” and “FAN,” stating that the complainant’s failure to confirm the email “constitutes a purely technical step related to account activation.” Finally, regarding the possible violation of Article 21 of the Regulation, the Company argued that it had acted on the request received on October 11, 2025, by arranging for the cessation of communications on the following November 3, thereby allegedly complying with the 30-day deadline provided for by the Regulation. Furthermore, the fact that an incorrect last name (similar to the complainant’s, differing only in the absence of a double “n” and the addition of a double “c”) had been entered in the website registration form allegedly caused a delay in processing the request. From a procedural standpoint, as previously mentioned, the Company had also requested in its briefs that a hearing be scheduled; however, after the Office had set the date, it notified the Company that it was waiving its right to the hearing (via note ref. no. 70838 dated May 8, 2026) “in light of the fact that, following the filing of the brief, no new elements or additional circumstances have emerged to be presented beyond what has already been fully set forth in the defense briefs, the undersigned Company hereby notifies that it waives the requested hearing.”

¶3

THE AUTHORITY’S ASSESSMENTS Based on the factual circumstances highlighted above and the assertions made in the defense brief—for which the Company is liable pursuant to Article 168 of the Code—the Authority confirms the violations identified in the notice of violation for the reasons set forth below.

¶3.1

REGARDING THE POSSIBLE VIOLATION OF ART. 157 OF THE CODE First, it is noted that the circumstances cited by the Company—which allegedly prevented it from responding to the Office—do not appear to involve elements (such as unforeseeable circumstances or force majeure) sufficient to constitute objectively insurmountable obstacles and, in any case, such as to exempt the Company from accountability for failing to respond to the Authority. In particular, while we understand the difficulties associated with appointing an external professional to the role of the Company’s DPO, a willingness to cooperate with the Authority would have required, at the very least, a timely explanation of those circumstances and difficulties to the Offices, accompanied, if necessary, by a request for a reasonable amount of time to provide the required response. In reality, however, the Company deemed it necessary to report its internal situation only after receiving notice of the initiation of proceedings pursuant to Art. 166 of the Code, thereby claiming an alleged objective impediment. It follows that the violation of Article 157 of the Code—which is hereby confirmed—stemmed from the Company’s internal decisions (those related to the change in the DPO) and from a corporate structure that demonstrated limitations in managing its relationship with this Authority.

ON THE ESTABLISHMENT OF THE CONTRACTUAL

¶3.2

RELATIONSHIP WITH THE COMPLAINANT With regard to the establishment of the pre-contractual and contractual relationship that would have entitled the Company to process the complainant’s personal data pursuant to Art. 6, para. 1, subparagraph (b) of the Regulation, it is important to note that the evidence presented in the case file and the arguments set forth in the defense brief do not appear sufficient to support the controller’s assertions. First, it is noted that the complainant denied ever having visited the controller’s website; in response, the Company has stated, on the contrary, that it recorded three visits allegedly attributable to the complainant (two on August 11, 2025, and one on September 5, 2025), providing as evidence an Excel file containing log data (Doc. 1 of the defense brief). According to the Company’s account, during those visits to its website, the complainant filled out the form on the site, accepted the General Terms and Conditions of the services offered, and reviewed the privacy policy. In light of the information in the case file, there is insufficient evidence to demonstrate the existence of a contractual relationship. In fact, it should be noted that the format of the Excel file submitted as evidence of the data subject’s access to the website does not provide the guarantees of immutability and integrity that the Data Protection Authority has deemed necessary in similar contexts (see Provision No. 654 of October 23, 2025—Web Doc. No. 10200530). Such strict evidentiary standards are considered particularly appropriate in cases, such as the one at hand, where the data subject disputes ever having visited the data controller’s website and denies ever having filled out any form. Furthermore, even a preliminary review of the information contained in Document 1, attached to the defense briefs, reveals some unusual elements; the first, highlighted by the Company itself, is the complainant’s last name (spelled incorrectly) and the fact that the same error appeared three times. The second element—which, given the dispute raised, might have warranted further investigation—relates to the three IP addresses listed in the Excel file, which, based on online checks, appear to be Canadian. Therefore, the only piece of information that could link visits to the website www.altroconsumo.it to the data subject would be the email address entered in the form. It follows that the aforementioned Document 1 attached to the defense briefs cannot be considered sufficient evidence of the circumstances presented by the Company, particularly in light of the additional peculiarities described above that characterize this specific case and given the data subject’s clear denial. Notwithstanding the lack of probative value of the documentation submitted, the additional arguments put forward by the Company also do not appear sufficient to support its claim regarding the existence of a contractual relationship with the data subject. According to the Company, in fact, the acquisition of FAN status was completed upon acceptance of the General Terms of Service and the subsequent registration on its website, specifying that the failure to confirm the email should be understood as a mere technical step and not as a double opt-in mechanism. Yet this account contradicts what the Company itself communicates to users who have filled out the form on the website. In fact, the first message sent to a user who has just filled out the aforementioned form has the subject line “You’re almost there: confirm your registration,” and the body of the email states the following: “You’re just one click away from accessing the benefits of Altroconsumo. To complete your registration, click on this link: Confirm your account.” This step appears to be secondary, given that the General Terms and Conditions established by the data controller define a “FAN” as: a consumer who has accepted these General Terms and Conditions of Service by registering on the Altroconsumo website via the designated registration form, thereby establishing a contractual relationship with Altroconsumo for the purpose of supporting its Mission.” It is therefore clear that the Company indicates that account confirmation is necessary to complete registration and thereby establish a contractual relationship with Altroconsumo and that, conversely, in the event of failure to confirm—as in the present case—the registration remains unconfirmed and incomplete and, consequently, the contractual relationship is not established. This also creates, in the unsuspecting data subject—who receives an email requesting confirmation of an account they never requested—the expectation that they will not unwittingly become a party to a contractual relationship they never wanted or sought. Furthermore, the evidence on file shows that if a user does not confirm their account, the Company sends two successive emails with content similar to the one mentioned above (requesting account confirmation to complete registration). If the User still fails to confirm, the system set up by the Company nevertheless begins sending promotional emails, as if the registration had been confirmed by the User. Upon closer examination, given how the account confirmation process works and the content of the messages sent to Users, the account confirmation notice functions more as a double opt-in mechanism rather than a mere technical step, as the Company has attempted to argue. Furthermore, interpreting the account confirmation mechanism in the terms described above (i.e., as a double opt-in mechanism) renders it unnecessary to disclose the data subject’s information to the processor for the purpose of providing (alleged) support for the conclusion of subscriptions to the Company’s services (pre-contractual context). In fact, given that the data subject did not respond to three communications, the subsequent telephone contact appears more like a last-ditch attempt to persuade the victim than a genuine willingness to provide unsolicited assistance. It should also be noted that, in this specific case, the email address was the only personal data that could be directly traced back to the User (in fact, the last name, entered three times, was incorrect, and the IP addresses of the connections were from Canada); any confirmation of the account via the User’s own email address would therefore have been a key factor that would have made it possible to verify, if necessary, the data subject’s actual intent and ensure the proper processing of personal data. On the other hand, the double opt-in mechanism appears to be an important measure for preventing unauthorized processing of data by a third party, thereby enabling 1) the protection of data subjects’ rights and 2) on the other hand, to ensure that the controller can verify the authenticity of the activities carried out on its website, especially in circumstances characterized by the peculiarities described above and the data subject’s denial of having filled out the form. Furthermore, precisely in relation to the second point mentioned, as will be further clarified in the following paragraphs, determining whether the contractual relationship was properly established is even more important for the Company, which, precisely on the basis of that contractual relationship, sends approximately 16–20 commercial communications per month to these Users, pursuant to Art. 130, paragraph 4, of the Code. Therefore, in light of evidence that is insufficient, in this specific case, to demonstrate the existence of a contractual relationship, and given the additional circumstances outlined above (in particular, the failure to confirm the account and the denial of having filled out the form), the processing of the complainant’s personal data based on the alleged contractual relationship (including the disclosure of data to the processor to finalize the purchase of subscriptions) is deemed unlawful as it violates Article 6(1)(b) of the Regulation.

ON THE PROCESSING OF DATA FOR

¶3.3

MARKETING PURPOSES Based on the findings regarding the (unproven) contractual relationship and the complainant’s denial of having filled out the form, there is also a lack of legitimate legal bases for the Company to send commercial communications. It should be noted, in fact, that Article 130, paragraph 2, of the Code provides that the sending of electronic communications for commercial purposes via (among other means) email is permitted only with the consent of the contracting party or user, with an exception allowed solely (as provided in paragraph 4 below) if the email address—and only the email address—was provided by the data subject in the context of a sale of similar goods or services, and provided, in such a case, the data subject retains the right to object at any time to receiving such communications. It should be noted that the briefs filed by the Company do not contain specific arguments regarding the objections raised on this point by the investigating authority. In the present case, in the absence of proof of a contractual relationship and confirmation of the account—and the consequent completion of the registration process—by the data subject, it is not possible to justify the sending of commercial communications by invoking, as a legal basis, the exemption provided for in the aforementioned Article 130, paragraph 4, of the Regulation. Therefore, it is necessary to verify the existence of a different legal basis for the Company’s processing for the purpose of sending commercial communications; on closer inspection, in the present case, the requirement of the data subject’s consent, pursuant to paragraph 2 of Article 130 of the Code, cited above, is also lacking. In fact, regarding consent for marketing purposes, the Company itself has stated that at the bottom of the form on its website there is only a checkbox indicating “I have read the privacy policy.” Therefore, through the form on its website, the Company does not appear to be obtaining any consent for the sending of commercial communications. In the present case, it must therefore be noted that there is no valid legal basis guaranteeing the lawfulness of the processing activities related to the Company’s sending of commercial communications. The violation of Articles 6 and 7 of the Regulation and Article 130 of the Code is therefore confirmed.

ON THE EXERCISE OF THE RIGHT

¶3.4

TO OBJECT BY THE DATA SUBJECT Regarding the objection to receiving further promotional messages, the complainant sent an initial form requesting access to personal data and objecting to the Company’s processor on September 17, 2025. On the same date, as instructed by the Company, this form was communicated to the Company, thereby acknowledging the complainant’s request. The form states: “2. Objection to processing for direct marketing purposes (Art. 21, paragraph 2 of Regulation (EU) 2016/679) The undersigned objects to the processing of data for the purposes of sending advertising or direct sales material, or for conducting market research or commercial communications.” […] A representative stated that she was calling on behalf of “Altroconsumo” and asked if I was interested in joining the Altroconsumo Association. The undersigned stated that he was not a data subject and asked how they had obtained his phone number. The woman explained that the undersigned had provided his phone number and email address on their website, requesting to be contacted. […] The undersigned confirmed that the email address was correct and reiterated that he was not interested in her offer.” From the contents of the form, it is therefore clear that the complainant did not wish to receive commercial communications regarding the Company’s products and services. Subsequently, the complainant reportedly resubmitted the same form directly to the controller on October 11, 2025. In response to the request to object, the Company acted on a date subsequent to November 3, 2025—the date of the last commercial communication received by the complainant, as documented by the Data Protection Authority’s Office during its investigation. The provisions of the Regulation regarding the exercise of rights stipulate that it is the controller who must provide a response and implement the request, facilitating the exercise of such rights and ensuring compliance “without undue delay” and, at the latest, within thirty days of receiving the request. (Article 12 of the Regulation). In the present case, it is not disputed that the complainant exercised his rights and, in particular, his right to object to processing for marketing purposes by the Company, and that he did so, initially, through the processor on September 17, 2025; in fact, as mentioned above, it was the processor himself who informed the controller of this exercise on the same date. On this point, the Company’s defense briefs confirm that “on September 17, 2025, […] the data processor notified Altroconsumo of the receipt of an email from […], who submitted an access request and an objection to the processing of data for marketing purposes (Doc. 3).” The marketing activities in question clearly related to the services offered by the controller. The Company, from a factual standpoint, therefore confirmed the above circumstance, also demonstrating awareness of the subject matter of the objection (i.e., commercial information regarding Altroconsumo’s services) raised by the data subject. In the present case, we are dealing with an exercise of the right to object made through the processor, who nevertheless conveyed the request to the controller and made the controller aware of it; this circumstance takes precedence over the existence of any other dedicated channels established by the Company, which—based on the evidence in the record—do not appear to have been duly brought to the data subject’s attention. Furthermore, from a procedural standpoint, it is important to note that the fact that the Company became aware of the data subject’s exercise of the right to object on September 17, 2025, is a detail that emerged only toward the end of the preliminary investigation, given the absence of any prior communication with the controller. Therefore, the deadline to be considered for the controller is precisely September 17, 2025, and the complainant’s subsequent reiteration of the same request is irrelevant. The complainant’s request for objection should therefore have been processed no later than thirty days after receipt of the request, that is, by October 17, 2025. In fact, the second submission of the objection request is redundant and unnecessary for the purpose of correctly reciting—as of September 2025— —the complainant’s relevant right to have been properly exercised; and, in any case, it would have been the Company’s duty to facilitate the exercise of that right by processing the objection request once it was communicated by the processor. This is all the more true given that the data subject had not even confirmed his account. If this were not the case, we would find ourselves having to require a data subject who has exercised their rights through a processor to repeat that exercise again with respect to the relevant controller—even when the latter has demonstrated awareness of the right to object exercised against them. Doing so, however, would impose an additional burden on the data subject (one not provided for by the law and which does not facilitate the exercise of the right), ultimately betraying the spirit of the safeguards established by the Regulation, which, in this regard, expressly provides for the processor’s obligation to assist the controller in addressing requests relating to Chapter III of the Regulation (Articles 28(3)(e) of the Regulation). According to the Company, however, having ceased sending marketing communications via email on November 3, 2025, would have ensured its proper fulfillment of its obligations. For the reasons set forth in detail above, however, the defenses raised by the controller on this point cannot be considered valid. Furthermore, the circumstances cited by the Company regarding the difficulty in identifying the complainant due to an incorrect surname entry in its database do not appear to be relevant. In fact, the processor encountered no difficulty in identifying the data subject based precisely on the information provided by the controller, and, in any case, the controller could have relied on its processor to resolve the request promptly. Consequently, a violation of Article 21 of the Regulation has also been established.

¶4

CONCLUSIONS In light of these considerations, the allegations set forth in the notice initiating the proceedings pursuant to Art. 166 of the Code are confirmed, as the statements made during the preliminary investigation, the defenses raised, and the evidence submitted to the record are insufficient to rebut the findings made by the Office; furthermore, none of the cases provided for in Art. 11 of Regulation No. 1/2019 apply. Therefore, the Authority finds that the controller’s conduct was unlawful for the following reasons: a) processing the complainant’s personal data without an appropriate legal basis; b) sending promotional communications to the complainant via email without meeting the conditions of lawfulness required by applicable law; c) failing to comply with the request to object within the time limits set forth in the Regulation, and d) failing to respond to the Office’s request for information dated March 31, 2026—all of which constitute violations of, respectively, a) Art. 6(1)(b) of the Regulation, b) Articles 6 and 7 of the Regulation as well as Article 130 of the Code; c) Article 21 of the Regulation; and d) Article 157 of the Code.

¶5

CORRECTIVE MEASURES Having established, under the aforementioned terms, that the data processing operations under review were unlawful, it is necessary to require the Company: a) pursuant to Article 58(2)(d) of the Regulation, to bring the processing operations into compliance with the provisions of the Regulation, using the legal basis set forth in Article 6, para 1, subparagraph b), only if the data subject has confirmed their account, ceasing the processing of those who have not done so and provided that no other legal grounds exist; b) pursuant to Article 58, para 2, subparagraph d) of the Regulation, to adopt appropriate technical and organizational measures to facilitate the exercise of the rights provided for by data protection legislation and to comply, without undue delay, the relevant requests, including the right to object, which may be exercised “at any time” by the data subject; c) pursuant to Article 157 of the Code, to notify the Authority, within 30 days of the notification of this order, of the steps taken to implement the measures imposed; Failure to comply with the provisions of this section may result in the imposition of the administrative fine provided for in Article 83(5) of the Regulation. Pursuant to Article 58(2)(i) of the Regulation and Article 166 of the Code, the Data Protection Authority has the power to impose an administrative fine pursuant to Article 83 of the Regulation, by issuing an injunction order (see Articles 18 of Law No. 689 of November 24, 1981, and 16(1) of the Data Protection Authority’s Regulation No. 1/2019).

¶6.1

Assessment of the Conduct and Determination of the Applicable Penalty Given that the violation of Articles 6, 7, and 21 of the Regulation and Article 130 of the Code occurred as a result of interrelated processing activities, Article 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the violations are all subject to the penalty provided for in Article 83, para 5, of the Regulation, as also referred to in Article 166, para 2, of the Code, the total amount of the penalty is to be set at up to 20,000,000 euros. The violation of Article 157 of the Code, on the other hand, constitutes a separate act attributable to the same data controller and must be considered separately for the purposes of determining the administrative penalty, the amount of which is likewise to be set at up to 20,000,000 pursuant to Article 83, para 5, of the Regulation, as also referred to in Article 166, para 2, of the Code. The amount of the fine to be imposed on the controller is therefore calculated based on the sum of the amounts corresponding to fines deemed effective, proportionate, and dissuasive for the aforementioned violations, as explained in greater detail below.

¶6.2

Determination of the Administrative Fine (Art. 83, para. 2, of the Regulation) The amount of the administrative fine must be determined based on the circumstances of each individual case, taking due account of the factors set forth in Art. 83(2) of the Regulation. In this regard, the economic conditions of the controller are relevant, as determined on the basis of the most recent available financial statements (for the year 2024), which show that the controller is an entity with a turnover of less than 500 million euros. a) That said, with regard to the violation of the provisions set forth in Articles 6, 7, and 21 of the Regulation and Article 130 of the Code, taking into account: - the nature and severity of the processing, which consisted of sending unsolicited commercial communications via email without causing substantial harm to the data subject, beyond mere annoyance, and complained of to date only by the complainant, as no other similar complaints against the same company have been received by the Authority (Art 83(2)(a) of the Regulation); - that it was possible to establish the existence of serious negligence with respect to the unlawful processing that occurred (Art. 83(2)(b) of the Regulation); - that the violation concerned the processing of only one type of personal data—contact information—relating to a single data subject (see Article 83(2)(g) of the Regulation); it is considered that, in the present case, the level of seriousness of the violations committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the Calculation of Administrative Fines under the GDPR” of May 24, 2023, paragraph 60). That said, it is considered that, for the purposes of determining the amount of the fine for the aforementioned violations, the following circumstances must be taken into account - the adoption of two previous decisions (Decision No. 429 of December 15, 2022, and Decision No. 823 of December 19, 2024) concerning relevant violations committed by the same data controller; and, in the case of Article 21 of the Regulation, by Decision No. 823 of December 19, 2024, the Authority also imposed a penalty for the same violation (see Article 83(2)(e) of the Regulation); - the complete lack of cooperation with the Authority during the preliminary investigation (see Article 83(2)(f) of the Regulation); - the fact that the Authority became aware of the violations as a result of a complaint filed by the data subject (see Article 83(2)(h) of the Regulation). In light of the aforementioned factors, evaluated as a whole, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Article 83(1) of the Regulation, for the violation of the provisions set forth in Articles 6, 7, and 21 of the Regulation and Article 130 of the Code, the Authority has determined the amount of the administrative fine to be 180,000 euros (one hundred eighty thousand/00). b) With regard to the violation of the provision set forth in Article 157 of the Code, taking into account: - the nature and severity of the processing, consisting of the failure to respond to the Office’s request for information (Article 83(2)(a) of the Regulation); - the seriously negligent nature of the data controller’s conduct (Art. 83(2)(b) of the Regulation); it is considered that, in this case as well, the level of severity of the violation committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60). That said, it is considered that, for the purposes of determining the amount of the fine, the following circumstances must be taken into account: - the absence of any relevant prior infringements committed by the same controller (see Art. 83(2)(e) of the Regulation); - the absence of any cooperation with the Authority during the investigation (see Article 83(2)(f) of the Regulation). In light of the aforementioned factors, assessed as a whole, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Art. 83, para 1, of the Regulation, for the violation of Article 157 of the Code, the amount of the monetary penalty is hereby set at 100,000 euros (one hundred thousand/00). In conclusion, as a result of the sum of the penalties quantified above, the total amount of the monetary penalty imposed on the data controller is set at 280,000 euros (two hundred eighty thousand/00). Finally, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the additional penalty of publishing this section of the decision—containing the injunction order—on the Data Protection Authority’s website must be applied, given the particularly serious nature of the violations detected. FOR THESE REASONS pursuant to Articles 57 and 83 of the Regulation, the processing of personal data by Altroconsumo Edizioni s.r.l., with registered office at Viale Piero e Alberto Pirelli, 10 - 20126 Milan, VAT No. 12581280158, is hereby declared unlawful due to the violation of Articles 6, 7, and 21 of the Regulation and Articles 130 and 157 of the Code, as set forth in the reasoning; a) Pursuant to Article 58(2)(d) of the Regulation, the company is ordered to bring its processing activities into compliance with the provisions of the Regulation, using the legal basis set forth in Article 6, para 1(b) only if the data subject has confirmed their account, ceasing the processing of those who have not done so and provided that no other legal bases exist; b) Pursuant to Article 58(2)(d) of the Regulation, it is required to adopt appropriate technical and organizational measures to facilitate the exercise of the rights provided for by data protection legislation and to respond, without undue delay, the relevant requests, including the right to object, which may be exercised “at any time” by the data subject; c) Pursuant to Article 157 of the Code, the Company is required to report to the Authority, within 30 days of notification of this order, the steps taken to implement the measures imposed; Failure to comply with the provisions of this section may result in the imposition of the administrative fine provided for in Article 83(5) of the Regulation. IT IS ORDERED pursuant to Articles 58(2)(i) and 83 of the Regulation, as well as Article 166 of the Code, the aforementioned controller is ordered to pay the total amount of 280,000 euros (two hundred eighty thousand/00) as an administrative fine for the violations set forth in the reasoning. IT IS ORDERED that the aforementioned controller, in the event that the dispute is not settled pursuant to Article 166, paragraph 8, of the Code, pay the total sum of 280,000 euros (two hundred eighty thousand/00), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It should be noted that, pursuant to Article 166, paragraph 8, of the aforementioned Code, the offender retains the right to settle the dispute by paying—again in accordance with the procedures set forth in the attachment— – of an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, provided for the filing of an appeal as indicated below; IT IS HEREBY ORDERED - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, that this decision be published on the Data Protection Authority’s website; - Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; - Pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violation(s) and the measures adopted in accordance with Article 58, para 2, of the Regulation in the Authority’s internal register provided for by Article 57, para 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the jurisdiction specified in the aforementioned Art 10, under penalty of inadmissibility, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori SEE ALSO Newsletter of July 29, 2026 [Web Doc. No. 10269624] Decision of June 18, 2026 Register of Decisions No. 464 of June 18, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003), (hereinafter the “Code”); HAVING REGARD TO Regulation No. 1/2019 concerning internal procedures with external relevance, aimed at carrying out the tasks and exercising the powers entrusted to the Data Protection Authority, approved by Resolution No. 98 of April 4, 2019, published in the Official Gazette No. 106 of May 8, 2019, and at www.gpdp.it, web doc. No. 9107633 (hereinafter “Regulation No. 1/2019 of the Data Protection Authority”); HAVING CONSIDERED the documentation on file; HAVING CONSIDERED the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority Regulation No. 1/2000 on the organization and operation of the office of the Data Protection Authority, adopted by resolution of June 28, 2000 (web doc. No. 1098801); REPORTER: Prof. Ginevra Cerrina Feroni; 1 FACTS AND COURSE OF THE PRELIMINARY INVESTIGATION 1.1 Origin of the preliminary investigation By letter dated November 4, 2025, entered into the record on the same date (Ref. No. 146057), a complaint was filed with this Authority alleging that the complainant had received unsolicited commercial communications via email from Altroconsumo Edizioni s.r.l., VAT No. 12581280158, located at Viale Piero e Alberto Pirelli, 10 - 20126 Milan (“Company”), in its capacity as the controller of the personal data processed through the website www.altroconsumo.it. On the merits, the complainant denied ever having submitted any request via the Company’s online form and, in any case, never confirmed “his account” to complete the registration process with Altroconsumo. Furthermore, in response to receiving numerous communications from the Company, the complainant also exercised his right to object to the processing of his personal data (in letters dated September 17, 2025, and October 11, 2025); however, he stated that he subsequently received additional promotional emails. 1.2 Actions Taken In a letter dated February 9, 2026 (Ref. No. 18848), the Office of the Data Protection Commissioner issued, pursuant to Article 157 of the Code, a request for information to the Company regarding the matters set forth in the aforementioned complaint. The request, which was duly delivered via certified email (PEC) on the same date, remained unanswered. 2 INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND SANCTIONING MEASURES AND THE PARTY’S DEFENSES 2.1 Initiation of proceedings (Article 166, paragraph 5, of the Code) Based on the above information and the evidence attached to the complaint, by a notice dated March 31, 2026 (Ref. No. 50043), served in accordance with Article 166, paragraph 5, of the Code, the Office initiated proceedings to adopt the measures referred to in Article 58, para 2, of the Regulation against the controller, inviting the latter to submit written defenses or documents to the Authority or to request a hearing before the Authority (Article 166, paragraphs 6 and 7, of the Code, as well as Article 18, paragraph 1, of Law No. 689 of November 24, 1981). The alleged violations in question concerned the following provisions: - Article 6, para 1, subparagraph b) of the Regulation, in that the processing carried out by the Company—in connection with the communications sent after the first email and in connection with the telephone contact by the processor—does not fall within the scope of pre-contractual measures taken at the request of the data subject; - Articles 6 and 7 of the Regulation and Article 130 of the Code, in that the Company processed the complainant’s personal data for marketing purposes without any appropriate legal basis; - Article 21 of the Regulation, in that the Company did not properly comply with the right to object exercised by the complainant; - Article 157 of the Code, in that the Company did not provide the information requested by the investigating authority. 2.2 Defenses of the Party (Article 166, paragraph 6, of the Code) The Company submitted written defenses regarding the proceedings against it and, after requesting a hearing before the Authority and having a date set for it, subsequently waived that right. Specifically, in a brief dated May 5, 2026 (Ref. No. 68431), the controller provided a general overview of the factual circumstances characterizing the case at hand, stating that it had processed the complainant’s personal data (including for marketing purposes) following visits made by the complainant himself to the website www.altroconsumo.it. Regarding the allegations raised by the investigating authority, the Company asserted, first, that the failure to respond to requests for information was linked to the handover between the previous (in-house) DPO and the new external professional appointed, effective January 1, 2026, to perform that function. According to the Company, this situation prevented it from providing the requested response “without any intention of evading its obligations to cooperate with the Authority.” The Company also argued that the pre-contractual/contractual relationship with the complainant had been properly established, even in the absence of account confirmation by the User, and that, therefore, the processing aimed at finalizing the purchase of a subscription to its services could legitimately be based on Art 6(1)(b) of the Regulation. In support of this argument, the Company cited its General Terms and Conditions regarding the definitions of “member” and “FAN,” stating that the complainant’s failure to confirm the email “represents a purely technical step related to account activation.” Finally, regarding the possible violation of Article 21 of the Regulation, the Company maintained that it had acted on the request received on October 11, 2025, by arranging for the cessation of communications on the following November 3, thereby allegedly complying with the 30-day deadline provided for by the Regulation. Furthermore, the fact that an incorrect last name had been entered in the website registration form (similar to the complainant’s, differing only by the omission of a double “n” and the addition of a double “c”) allegedly caused a delay in processing the request. From a procedural standpoint, as previously mentioned, the Company had also requested in its briefs that a hearing be scheduled; however, after the Office had set the date, it notified the Company that it was waiving its right to the hearing (via note ref. no. 70838 dated May 8, 2026) “in light of the fact that, following the filing of the brief, no new elements or additional circumstances have emerged to be presented beyond what has already been fully set forth in the defense briefs, the undersigned Company hereby notifies that it waives the requested hearing.” 3 THE AUTHORITY’S ASSESSMENTS Based on the factual circumstances highlighted above and the assertions made in the defense brief—for which the Company is liable pursuant to Article 168 of the Code—the Authority confirms the violations identified in the notice of violation for the reasons set forth below. 3.1 REGARDING THE POSSIBLE VIOLATION OF ARTICLE 157 OF THE CODE First, it is noted that the circumstances cited by the Company—which allegedly prevented it from responding to the Office—do not appear to involve elements (such as unforeseeable circumstances or force majeure) sufficient to constitute objectively insurmountable obstacles and, in any case, such as to exempt the Company from accountability for failing to respond to the Authority. In particular, while we understand the difficulties associated with appointing an external professional to the role of the Company’s DPO, a willingness to cooperate with the Authority would have required, at the very least, a timely explanation of those circumstances and difficulties to the Office, accompanied, if necessary, by a request for a reasonable amount of time to provide the required response. In reality, however, the Company deemed it necessary to report its internal situation only after receiving notice of the initiation of proceedings pursuant to Art. 166 of the Code, thereby claiming an alleged objective impediment. It follows that the violation of Article 157 of the Code—which is hereby confirmed—stemmed from the Company’s internal decisions (those related to the change in the DPO) and from a corporate structure that demonstrated limitations in managing its relationship with this Authority. 3.2 ON THE ESTABLISHMENT OF THE CONTRACTUAL RELATIONSHIP WITH THE COMPLAINANT With regard to the establishment of the pre-contractual and contractual relationship that would have entitled the Company to process the complainant’s personal data pursuant to Article 6(1), para 1, subparagraph (b) of the Regulation, it is important to note that the evidence presented in the case file and the arguments put forward in the defense brief do not appear sufficient to support the controller’s assertions. First, it should be noted that the complainant denied ever having visited the controller’s website; in contrast, the Company has stated, on the contrary, that it recorded three visits allegedly attributable to the complainant (two on August 11, 2025, and one on September 5, 2025), providing in support an Excel file containing log data (Doc. 1 of the defense brief). According to the Company’s account, during these visits to its website, the complainant allegedly filled out the form on the site, accepted the General Terms and Conditions of the services offered, and reviewed the privacy policy. In light of the evidence on file, there is insufficient evidence to demonstrate the existence of a contractual relationship. In fact, it should be noted that the format of the Excel file submitted as evidence of the data subject’s access to the website does not provide the guarantees of immutability and integrity that the Data Protection Authority has deemed necessary in similar contexts (see Provision No. 654 of October 23, 2025—Web Doc. No. 10200530). Such strict evidentiary standards are deemed particularly appropriate in cases, such as the present one, where the data subject disputes ever having visited the data controller’s website, denying ever having filled out any form. Furthermore, even a preliminary review of the information contained in Document 1, attached to the defense briefs, reveals some unusual elements; the first, highlighted by the Company itself, is the complainant’s last name (spelled incorrectly) and the fact that the same error appeared three times. The second element—which, in light of the dispute raised, might have warranted further investigation—relates to the three IP addresses listed in the Excel file, which, based on online checks, appear to be Canadian. Therefore, the only piece of information that could link visits to the website www.altroconsumo.it to the data subject would be the email address entered in the form. It follows that the aforementioned Document 1 attached to the defense briefs cannot be considered sufficient evidence of the circumstances alleged by the Company, particularly in light of the additional peculiarities described above that characterize this case and given the data subject’s clear denial. Notwithstanding the lack of probative value of the documentation submitted, the additional arguments put forward by the Company also do not appear sufficient to support its claim regarding the existence of a contractual relationship with the data subject. According to the Company, in fact, the acquisition of FAN status was completed upon acceptance of the General Terms of Service and the subsequent registration on its website, specifying that failure to confirm the email should be understood as a mere technical step and not as a double opt-in mechanism. Yet this account contradicts what the Company itself communicates to users who have filled out the form on its website. In fact, the first message sent to a user who has just filled out the aforementioned form has the subject line “You’re almost there: confirm your registration,” and the body of the email states the following: “You’re just one click away from accessing the benefits of Altroconsumo. To complete your registration, click on this link: Confirm your account.” This step appears secondary, given that the General Terms and Conditions established by the data controller define a “FAN” as: a consumer who has accepted these General Terms and Conditions of Service by registering on the Altroconsumo website via the designated registration form, thereby establishing a contractual relationship with Altroconsumo for the purpose of supporting its Mission.” It is therefore clear that the Company indicates that account confirmation is necessary to complete registration and thereby establish a contractual relationship with Altroconsumo and that, conversely, in the event of failure to confirm—as in the present case—the registration remains unconfirmed and incomplete and, consequently, the contractual relationship is not established. This also creates, in the unsuspecting data subject—who receives an email requesting confirmation of an account they never requested—the expectation that they will not unwittingly become a party to a contractual relationship they never wanted or sought. Furthermore, the evidence on file shows that if a user does not confirm their account, the Company sends two subsequent emails with content similar to the one mentioned above (requesting account confirmation to complete registration). If the User still fails to confirm, the system set up by the Company nevertheless begins sending promotional emails, as if the registration had been confirmed by the User. Upon closer examination, given how the account confirmation process operates and the wording of the messages sent to Users, the account confirmation communication constitutes more of a double opt-in mechanism than a mere technical step, as the Company has sought to argue. Furthermore, interpreting the account confirmation mechanism in the terms described above (i.e., as a double opt-in mechanism) renders it unnecessary to disclose the data subject’s information to the processor for the purpose of providing (alleged) support for the conclusion of subscriptions to the Company’s services (pre-contractual context). In fact, given that the data subject did not respond to three prior communications, the subsequent telephone contact appears more like a last-ditch attempt to persuade the victim than a genuine willingness to provide unsolicited assistance. It should also be noted that, in this specific case, the email address was the only piece of personal data that could be directly linked to the User (in fact, the last name, entered three times, was incorrect, and the IP addresses of the connections were from Canada); any confirmation of the account via the User’s own email address would therefore have been a key element that would have made it possible to verify, if necessary, the data subject’s actual intent and the consequent proper processing of personal data. On the other hand, the double opt-in mechanism appears to be an important measure to prevent unauthorized processing of data by a third party, thereby enabling 1) the protection of data subjects’ rights and 2) on the other hand, to ensure that the controller can verify the authenticity of the activities carried out on its website, especially in circumstances characterized by the peculiarities described above and the data subject’s denial of having filled out the form. Furthermore, precisely in relation to the second point mentioned, as will be further clarified in the following paragraphs, determining whether the contractual relationship was properly established is even more important for the Company, which, precisely on the basis of that contractual relationship, sends approximately 16–20 commercial communications per month to these Users, pursuant to Art. 130, paragraph 4, of the Code. Therefore, in light of evidence that is insufficient, in this specific case, to demonstrate the existence of a contractual relationship, and given the additional circumstances outlined above (in particular, the failure to confirm the account and the denial of having filled out the form), the processing of the complainant’s personal data based on the alleged contractual relationship (including the disclosure of data to the processor to finalize the purchase of subscriptions) is deemed unlawful as it violates Article 6(1)(b) of the Regulation. 3.3 ON THE PROCESSING OF DATA FOR MARKETING PURPOSES Based on the findings regarding the (unproven) contractual relationship and the complainant’s denial of having filled out the form, there is also a lack of legitimate legal bases for the Company to send commercial communications. It should be noted, in fact, that Article 130, paragraph 2, of the Code provides that the sending of electronic communications for commercial purposes via (among other means) email is permitted only with the consent of the contracting party or user, with an exception allowed solely (as provided in paragraph 4 below) if the email address—and only the email address—was provided by the data subject in the context of a sale of similar goods or services, and provided, in such a case, the data subject retains the right to opt out of receiving such communications at any time. It should be noted that the briefs filed by the Company do not contain specific arguments regarding the objections raised on this point by the investigating authority. In the present case, in the absence of proof of a contractual relationship and confirmation of the account—and the consequent completion of the registration process—by the data subject, it is not possible to justify the sending of commercial communications by invoking, as a legal basis, the exemption provided for in the aforementioned Article 130, paragraph 4, of the Regulation. Therefore, it is necessary to verify the existence of a different legal basis for the Company’s processing for the purpose of sending commercial communications; on closer inspection, in the present case, the requirement for the data subject’s consent, pursuant to paragraph 2 of Article 130 of the Code, cited above, is also lacking. In fact, regarding consent for marketing purposes, the Company itself has stated that at the bottom of the form on its website there is only a checkbox indicating “acknowledgment of the privacy policy.” Therefore, through the form on its website, the Company does not appear to be obtaining any consent for the sending of commercial communications. In the present case, it must therefore be noted that there is no valid legal basis guaranteeing the lawfulness of the processing activities related to the Company’s sending of commercial communications. Consequently, the violation of Articles 6 and 7 of the Regulation and Article 130 of the Code is confirmed. 3.4 ON THE EXERCISE OF THE RIGHT TO OBJECT BY THE DATA SUBJECT Regarding the objection to receiving further promotional messages, the complainant sent an initial form requesting access to personal data and objecting to the Company’s processor on September 17, 2025. On the same date, as instructed by the Company, this form was communicated to the Company, thereby acknowledging the complainant’s request. The form states: “2. Objection to processing for direct marketing purposes (Art. 21, paragraph 2 of Regulation (EU) 2016/679) The undersigned objects to the processing of data for the purpose of sending advertising material or direct sales, or for conducting market research or commercial communications. […] A representative stated she was calling on behalf of “Altroconsumo” and asked if he was a data subject. The undersigned stated he was not a data subject and asked how the information regarding his phone number had been obtained. The woman explained that the undersigned had provided his phone number and email address on their website, requesting to be contacted. […] The undersigned confirmed that the email address was correct and reiterated that he was not interested in her offer.” From the contents of the form, it is therefore clear that the complainant does not wish to receive commercial communications regarding the Company’s products and services. Subsequently, the complainant appears to have resubmitted the same form directly to the controller on October 11, 2025. In response to the objection request, the Company acted on a date subsequent to November 3, 2025, the date of the last commercial communication received by the complainant, as documented by the Data Protection Authority’s Office during its investigation. The provisions of the Regulation regarding the exercise of rights stipulate that the controller must provide a response and implement the request, facilitating the exercise of such rights and ensuring compliance “without undue delay” and, at the latest, within thirty days of receiving the request. (Article 12 of the Regulation). In the present case, it is not disputed that the complainant exercised his rights—and, in particular, his right to object to processing for marketing purposes by the Company—and that he did so, initially, through the processor on September 17, 2025; in fact, as mentioned above, the processor himself informed the controller of this exercise on the same date. On this point, the Company’s defense briefs confirm that “on September 17, 2025, […] it notified Altroconsumo of the receipt of an email from […], who submitted an access request and an objection to the processing of data for marketing purposes (Doc. 3).” The marketing activities in question clearly related to the services offered by the controller. From a factual standpoint, therefore, the Company confirmed the circumstance described above, also demonstrating awareness of the subject matter of the objection (i.e., commercial information regarding Altroconsumo’s services) raised by the data subject. In the present case, we are dealing with the exercise of the right to object, which was exercised through the processor, who nevertheless conveyed the request to the controller and made the controller aware of it; this circumstance takes precedence over the existence of any other dedicated channels established by the Company, which—based on the evidence in the record—do not appear to have been duly brought to the data subject’s attention. Furthermore, from a procedural standpoint, it is important to note that the fact that the Company became aware of the data subject’s exercise of the right to object on September 17, 2025, is a fact that emerged only toward the end of the preliminary investigation, given the absence of any preliminary communication with the controller. Therefore, the deadline to be considered for the controller is precisely September 17, 2025, and the complainant’s subsequent reiteration of the same request is irrelevant. The complainant’s request for objection should therefore have been processed no later than thirty days after receipt of the request, that is, by October 17, 2025. In fact, the second submission of the objection request is redundant and unnecessary for the purpose of correctly reciting—as of September 2025— —the complainant’s relevant right had been properly exercised as of September 2025; and, in any case, it would have been the Company’s duty to facilitate the exercise of that right by processing the request to object once it was communicated by the processor. This is all the more true given that the data subject had not even verified his account. If this were not the case, we would find ourselves having to require a data subject, who has exercised their rights through a processor, to repeat that exercise even with respect to the relevant controller—even when the latter has demonstrated awareness of the right to object exercised against them. Doing so, however, would impose an additional burden on the data subject (one not provided for by the law and which does not facilitate the exercise of the right), ultimately betraying the spirit of the safeguards established by the Regulation, which, in this regard, expressly provides for the processor’s obligation to assist the controller in addressing requests relating to Chapter III of the Regulation (Articles 28, para 3, subparagraph e of the Regulation). According to the Company, however, ceasing to send marketing communications via the email dated November 3, 2025, would have ensured proper fulfillment of its obligations. For the reasons set forth in detail above, however, the defenses raised by the controller on this point cannot be considered valid. Furthermore, the circumstances cited by the Company regarding the difficulty in identifying the complainant due to an incorrect surname entry in its database do not appear relevant either. In fact, the processor encountered no difficulty in identifying the data subject based precisely on the information provided by the controller, and, in any case, the controller could have relied on its processor to resolve the request promptly. Consequently, a violation of Article 21 of the Regulation has also been established. 4 CONCLUSIONS In light of these considerations, the allegations set forth in the notice initiating the proceedings pursuant to Art. 166 of the Code are confirmed, as the statements made during the preliminary investigation, the defenses raised, and the evidence submitted in the case file are insufficient to rebut the findings made by the Office; furthermore, none of the cases provided for in Art. 11 of Regulation No. 1/2019 apply. Therefore, the Authority finds that the controller’s conduct was unlawful for the following reasons: a) processing the complainant’s personal data without an appropriate legal basis; b) sending promotional communications to the complainant via email without meeting the conditions of lawfulness required by applicable law; c) failing to comply with the request to object within the time limits set forth in the Regulation, and d) failing to respond to the Office’s request for information dated March 31, 2026, all of which constitute violations of, respectively, a) Article 6(1)(b) of the Regulation, b) Articles 6 and 7 of the Regulation as well as Article 130 of the Code; c) Article 21 of the Regulation; and d) Article 157 of the Code. 5 CORRECTIVE MEASURES Having established, under the aforementioned terms, that the data processing operations under review were unlawful, it is necessary to require the Company: a) pursuant to Article 58(2)(d) of the Regulation, to bring the processing operations into compliance with the provisions of the Regulation, using the legal basis set forth in Article 6, para 1, subparagraph b), only if the data subject has confirmed their account, ceasing the processing of those who have not done so and provided that no other legal bases exist; b) pursuant to Article 58(2)(d) of the Regulation, to adopt appropriate technical and organizational measures to facilitate the exercise of the rights provided for by data protection legislation and to respond, without undue delay, the relevant requests, including the right to object, which may be exercised “at any time” by the data subject; c) pursuant to Article 157 of the Code, to notify the Authority, within 30 days of the notification of this order, of the actions taken to implement the measures imposed; Failure to comply with the provisions of this point may result in the imposition of the administrative fine provided for in Art. 83(5) of the Regulation. Pursuant to Article 58(2)(i) of the Regulation and Article 166 of the Code, the Data Protection Authority has the power to impose an administrative fine pursuant to Article 83 of the Regulation, by issuing an injunction order (see Articles 18 of Law No. 689 of November 24, 1981, and 16(1) of the Data Protection Authority’s Regulation No. 1/2019). 6.1 Assessment of the Conduct and Determination of the Applicable Sanction Given that the violation of Articles 6, 7, and 21 of the Regulation and Article 130 of the Code occurred as a result of interrelated processing operations, Article 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the violations are all subject to the penalty provided for in Article 83, para 5, of the Regulation, as also referred to in Article 166, para 2, of the Code, the total amount of the fine is to be set at up to 20,000,000 euros. The violation of Article 157 of the Code, on the other hand, constitutes a separate act attributable to the same data controller and must be considered separately for the purposes of determining the administrative penalty, the amount of which is likewise to be set at up to 20,000,000 pursuant to Article 83, para 5, of the Regulation, as also referred to in Article 166, para 2, of the Code. The amount of the penalty to be imposed on the controller is therefore determined based on the sum of the amounts corresponding to penalties deemed effective, proportionate, and dissuasive for the aforementioned violations, as explained in greater detail below. 6.2 Determination of the Administrative Fine (Article 83(2) of the Regulation) The amount of the administrative fine must be determined based on the circumstances of each individual case, taking due account of the factors set forth in Art. 83(2) of the Regulation. In this regard, the economic conditions of the controller are relevant, as determined on the basis of the most recent available financial statements (for the year 2024), which show that the controller is an entity with a turnover of less than 500 million euros. a) That said, with regard to the violation of the provisions set forth in Articles 6, 7, and 21 of the Regulation and Article 130 of the Code, taking into account: - the nature and severity of the processing, which consisted of sending unsolicited commercial communications via email without causing substantial harm to the data subject, beyond mere annoyance, and complained of to date only by the complainant, as no other similar complaints against the same company have been received by the Authority (Article 83(2)(a) of the Regulation); - that it was possible to establish the existence of serious negligence regarding the unlawful processing that occurred (Art. 83(2)(b) of the Regulation); - that the violation concerned the processing of only one type of personal data—contact information—relating to a single data subject (see Article 83(2)(g) of the Regulation); it is considered that, in the present case, the level of seriousness of the violations committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the Calculation of Administrative Fines under the GDPR” of May 24, 2023, paragraph 60). That said, it is considered that, for the purposes of determining the amount of the fine for the aforementioned violations, the following circumstances must be taken into account - the adoption of two previous decisions (Decision No. 429 of December 15, 2022, and Decision No. 823 of December 19, 2024) concerning relevant violations committed by the same data controller; and, in the case of Article 21 of the Regulation, by Decision No. 823 of December 19, 2024, the Authority also imposed a sanction for the same violation (see Article 83(2)(e) of the Regulation); - the complete lack of cooperation with the Authority during the preliminary investigation (see Art. 83(2)(f) of the Regulation); - the fact that the Authority became aware of the violations as a result of a complaint filed by the data subject (see Article 83(2)(h) of the Regulation). In light of the aforementioned factors, considered as a whole, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Article 83(1) of the Regulation, for the violation of the provisions set forth in Articles 6, 7, and 21 of the Regulation and Article 130 of the Code, it is hereby determined that the amount of the monetary penalty shall be 180,000 euros (one hundred eighty thousand/00). b) With regard to the violation of the provision set forth in Article 157 of the Code, taking into account: - the nature and severity of the processing, consisting of the failure to respond to the Office’s request for information (Article 83(2)(a) of the Regulation); - the nature of the data controller’s conduct, which constituted gross negligence (Article 83(2)(b) of the Regulation); it is considered that, in this case as well, the level of severity of the violation committed by the controller is moderate (see European Data Protection Board, “Guidelines 4/2022 on the calculation of administrative fines under the GDPR” of May 24, 2023, paragraph 60). That said, it is considered that, for the purposes of quantifying the fine, the following circumstances must be taken into account: - the absence of any relevant prior violations committed by the same data controller (see Article 83(2)(e) of the Regulation); - the absence of any cooperation with the Authority during the investigation (see Article 83(2)(f) of the Regulation). In light of the aforementioned factors, assessed as a whole, and in accordance with the principles of effectiveness, proportionality, and deterrence set forth in Art. 83, para 1, of the Regulation, for the violation of Article 157 of the Code, the amount of the monetary penalty is hereby set at 100,000 euros (one hundred thousand/00). In conclusion, as a result of the sum of the penalties quantified above, the amount of the monetary penalty imposed on the data controller is set at 280,000 euros (two hundred eighty thousand/00). Finally, pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the additional penalty of publishing this section of the decision containing the injunction order on the Data Protection Authority’s website must be applied, given the particularly serious nature of the violations found. FOR THESE REASONS pursuant to Articles 57 and 83 of the Regulation, the processing of personal data carried out by Altroconsumo Edizioni s.r.l., with registered office at Viale Piero e Alberto Pirelli, 10 - 20126 Milan, VAT No. 12581280158, is hereby declared unlawful due to the violation of Articles 6, 7, and 21 of the Regulation and Articles 130 and 157 of the Code, as set forth in the reasoning; a) Pursuant to Article 58(2)(d) of the Regulation, the company is ordered to bring its processing activities into compliance with the provisions of the Regulation, using the legal basis set forth in Article 6, para 1(b) only if the data subject has confirmed their account, ceasing the processing of those who have not done so and provided that no other legal bases exist; b) Pursuant to Article 58(2)(d) of the Regulation, it is required to adopt appropriate technical and organizational measures to facilitate the exercise of the rights provided for by data protection legislation and to respond, without undue delay, the relevant requests, including the right to object, which may be exercised “at any time” by the data subject; c) Pursuant to Article 157 of the Code, the data controller is required to notify the Authority, within 30 days of the notification of this order, of the actions taken to implement the measures imposed; Failure to comply with the provisions of this point may result in the imposition of the administrative fine provided for in Article 83(5) of the Regulation. IT IS ORDERED pursuant to Articles 58(2)(i) and 83 of the Regulation, as well as Article 166 of the Code, the aforementioned controller is hereby ordered to pay the total sum of 280,000 euros (two hundred eighty thousand/00) as an administrative fine for the violations set forth in the grounds. IT IS ORDERED that the aforementioned controller, in the event that the dispute is not settled pursuant to Article 166, paragraph 8, of the Code, pay the total sum of 280,000 euros (two hundred eighty thousand/00), in accordance with the procedures set forth in the attachment, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is noted that, pursuant to Article 166, paragraph 8, of the aforementioned Code, the offender retains the right to settle the dispute by paying—again in accordance with the procedures set forth in the attachment – of an amount equal to half of the imposed penalty within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below; IT IS HEREBY ORDERED - pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, that this decision be published on the Data Protection Authority’s website; - Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019, the publication of the injunction order on the Data Protection Authority’s website; - Pursuant to Art. 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violation(s) and the measures adopted in accordance with Article 58, para 2, of the Regulation in the Authority’s internal register provided for by Article 57, para 1, letter u), of the Regulation. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the jurisdiction specified in the aforementioned Art 10, under penalty of inadmissibility, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, June 18, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Cerrina Feroni THE SECRETARY GENERAL Montuori

How it connects

13 of 16 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… First Chamber Jan 12, 2023 Right of Access Personal Data Recipient
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Het Hof van Justitie van de EU (Eerste Kamer) beantwoordt een prejudiciële vraag over de uitleg van artikel 13 van Richtlijn 2002/58/EC (ePrivacy) en de verhouding tot de GDPR,… Mar 27, 2025 Telecommunications Personal Data Marketing
C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… First Chamber Jun 22, 2023 Right of Access Personal Data Right to Restriction