Threat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mapping

Altroconsumo Edizioni S.r.l.medium

Sign-up never completed, marketing emails sent anyway: EUR 280,000

Italy's data protection authority has fined Altroconsumo Edizioni S.r.l. EUR 280,000 for using data collected through its own website for email marketing, and for delays in responding to data subject rights requests. The inquiry started from a single person's complaint: she was receiving promotional messages despite having already asked not to, and had never completed the membership form. The investigation found the user registration procedure lacked adequate technical measures: leaving the sign-up half-finished was enough for the data to end up in the promotional pipeline anyway. Beyond the fine, a ban on processing the data of anyone who never confirmed their account.

One complaint, one person

Privacy fines that make the papers usually start from an event: a data breach, an own-initiative inquiry, a mass report. Not this one. This one starts from one person writing to the authority to say, in substance: I keep getting marketing emails, I already asked not to receive them, and on top of that I never signed up.

The Italian data protection authority fined Altroconsumo Edizioni S.r.l. EUR 280,000 over the use, for email marketing purposes, of data collected through the www.altroconsumo.it website, and over delays in responding to data subject rights requests.

The identity of the recipient is worth noting, because it makes the case more instructive rather than less: Altroconsumo is Italy's leading consumer protection organisation. Not an aggressive marketing operator. Which suggests the problem found was not a cynical commercial choice but something more mundane and far more widespread — a process defect that simply stayed there.

What was established

EUR 280,000
fine
Altroconsumo Edizioni S.r.l.
1
complaint at the origin
from a person who only asked to be left alone
Ban
on processing the data
of anyone who never confirmed account creation

The technical point is the most interesting one, and worth stating precisely because it is replicable across thousands of websites.

The complainant had never filled in the form to become a member. The company, for its part, was unable to demonstrate the correctness of the contractual relationship that would have justified the sending.

The investigation found that the user registration procedure did not include adequate technical measures. In operational terms: anyone who started a sign-up and abandoned it halfway — without confirming, without completing — ended up in the pool from which promotional messages were later sent.

Beyond the fine, the authority ordered the company to stop processing the data of those who had not confirmed account creation and to bring its procedures into line with the GDPR.

Why this is a security case, not just a marketing one

The natural objection is that this is advertising compliance, not information security. It is an objection worth dismantling, because the boundary is less sharp than it looks.

Data collected without a legal basis is data nobody knows how to look after. If nobody knows those people are in the archive, nobody puts that archive in the record of processing activities, nobody includes it in the risk assessment, nobody decides how long to keep it. It is an archive invisible to the organisation that holds it — and perfectly visible to anyone who gets in.

Minimisation is a security measure, not a paperwork exercise. The data you do not collect is the data you cannot lose. A list of never-completed sign-ups is, by definition, a list nobody has any reason to defend.

Delays in responding are a symptom. The GDPR grants a month to answer someone exercising their rights, extendable in complex cases. When that deadline slips, it usually is not bad faith: it is that no process connects the request received to the systems actually holding the data. And that is the same capability an incident demands — knowing where the data is and who is in it. An organisation that cannot answer one person asking what do you hold on me within a month will not manage, within 72 hours, to tell a regulator how many people a breach involved.

The half-filled form

  1. 01
    The user
    starts registering on the site
  2. 02
    The user
    never confirms: closes the tab, changes their mind, gets distracted
  3. 03
    The system
    keeps the record anyway and exposes it to marketing
  4. 04
    The effect
    promotional messages to people who never completed anything

There is a comfortable way to tell this story — a company emailing people who did not want it — and a more useful one: consent is not a moment, it is a state, and the system has to distinguish a sign-up that was started from one that was finished.

It is a distinction almost every online registration form has to make. The user types their email, then the phone rings, then the train, then the day. But the data has already reached the server. What happens to it is a technical decision, taken by somebody months or years earlier, often without much thought: keeping it so the sign-up can be resumed later is reasonable; treating it as a sign-up is not.

The operational lesson is the same for any site collecting contacts: you need an explicit flag saying whether registration was confirmed, and everything downstream — sending, profiling, enrichment — has to read that flag. If it does not exist, the implicit choice has already been made, and it is not the right one.

What we do not know

The full text of the decision was not consulted directly in this verification: what is reported here follows the Italian DPA communication of 29 July 2026 and its newsletter no. 550. The authority's portal responds unreliably to automated requests, and that is a declared limit of this reconstruction.

Not public — or at least not verified by us — are the number of people involved, the exact period the defect stayed active, the criteria used to set the amount, and whether the company intends to appeal. The appeal window runs from service of the decision, not from the news.

What to take away

Check what your registration form does with incomplete sign-ups. This is not a question for legal: it is a question for whoever wrote the code, and the answer is almost always in the database, not in the privacy policy.

Check that marketing consent is separate and traceable. Separate from signing up for the service, and with a record saying when and through which screen it was given. In a dispute, the burden of proof sits with the controller.

Time your responses to rights requests. If you do not know how long you take to answer an access request, you take too long.

Treat the record of processing activities as a security inventory. It is the only document that, kept honestly, says which archives actually exist. It matters in an inspection, and it matters on the day you need to know what was lost.

The point

A half-filled form is not consent. It is a half-filled form.

Obvious enough written out like that. It costs EUR 280,000 when nobody wrote it into the system.

More dossiers