PrivacyForgeSign In
Back to Blog

Abandoned Cart Email and GDPR: Which Legal Basis Applies

Italy fined a company €280,000 for emailing people who never confirmed their sign-up. Here is which GDPR legal basis actually covers abandoned cart email.

PFMariyan ValevJul 30, 2026 · 14 min read
GuideGuide

Key Takeaways

  • On 29 July 2026, Italy's Garante fined Altroconsumo Edizioni Srl €280,000, in part for sending promotional email to people who started a website registration and never confirmed it.
  • The finding was not "you needed consent" in the abstract. It was that the company treated the contractual relationship as concluded when the user had actively declined to confirm the account.
  • EDPB guidance is explicit that the pre-contractual limb of Article 6(1)(b) "would not cover unsolicited marketing or other processing which is carried out solely on the initiative of the data controller."
  • An abandoned cart and an abandoned registration are different legal situations. One follows a step the customer asked you to take; the other follows a step they walked away from.
  • The remedy the Garante ordered was cessation and redesign — stop processing the data of everyone who never confirmed, and bring the procedure into line — not a more prominent unsubscribe link.

Introduction

Somebody typed their address into your sign-up form last Tuesday, got as far as the confirmation screen, and closed the tab. Your marketing platform counted them as a lead. Three days later they received a welcome sequence.

That flow now carries a price. On 29 July 2026, Italy's Garante per la protezione dei dati personali fined Altroconsumo Edizioni Srl €280,000. Part of the reason: even when users decided not to confirm the account creation, and therefore not to register on the site, the company still treated the contractual relationship as concluded — and sent promotional email anyway.

If you run cart-recovery or signup-recovery email, this decision is aimed squarely at your stack. It also puts a regulator's answer, with a number attached, on a question practitioners have been arguing about in Shopify and Klaviyo community threads since 2018.

Marketing email to a non-customer needs a lawful basis under GDPR Article 6 before anything else is worth discussing. Three are plausible for recovery email, and only one of them survives contact with an abandoned registration.

Consent — Article 6(1)(a)

Article 6(1)(a) applies where "the data subject has given consent to the processing of his or her personal data for one or more specific purposes." The bar for what counts as consent is where most recovery flows fail.

The EDPB's Guidelines 05/2020 on consent (Version 1.1, adopted 4 May 2020) put it plainly at paragraph 79: "The use of pre-ticked opt-in boxes is invalid under the GDPR. Silence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice."

Paragraph 77 adds that a "clear affirmative act" means "the data subject must have taken a deliberate action to consent to the particular processing." Typing an address into a field so you can send a confirmation link is a deliberate action aimed at receiving the confirmation link. It is not, by itself, a deliberate action aimed at receiving your product newsletter.

Contract and pre-contractual steps — Article 6(1)(b)

Article 6(1)(b) covers processing "necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract." That second limb is the one every cart-recovery vendor reaches for, and it is narrower than it looks.

The EDPB's Guidelines 2/2019 on Article 6(1)(b) in online services (Version 2.0, adopted 8 October 2019) set the test at paragraph 22: the processing must be "objectively necessary for the performance of a contract with a data subject, or … objectively necessary in order to take pre-contractual steps at the request of a data subject."

Paragraph 46 confirms the limb can apply even when it is unclear whether a contract will be concluded — "as long as the data subject makes the request in the context of potentially entering into a contract and the processing in question is necessary to take the steps requested." The worked example is a shopper entering a postal code to check whether a service covers their area.

Then paragraph 47 closes the door: "In any case, this provision would not cover unsolicited marketing or other processing which is carried out solely on the initiative of the data controller, or at the request of a third party."

Read together, the line is clear: doing the thing the shopper asked for is covered, and deciding on your own initiative to market to them afterwards is not.

Legitimate interests — Article 6(1)(f)

Article 6(1)(f) permits processing "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject."

Recital 47 is more useful than the article here. It confirms that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest" — but it conditions the whole basis on "the reasonable expectations of data subjects based on their relationship with the controller," and warns that a data subject's rights "could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing."

Reasonable expectations is the hinge. Someone who filled a basket and left has a relationship with your store and can plausibly expect a nudge. Someone who declined to confirm an account has expressed the opposite expectation, in the clearest way the interface allowed.

A note on scope: Article 6 is only the first gate. ePrivacy rules govern the send itself — in the UK, PECR Regulation 22, which bars unsolicited marketing email unless "the recipient of the electronic mail has previously notified the sender that he consents for the time being to such communications." Clearing Article 6 does not clear PECR.

What the Garante Actually Found in the €280,000 Altroconsumo Case

The Garante's newsletter of 29 July 2026 describes the failure in process terms. Altroconsumo, "nella procedura di registrazione degli utenti al proprio sito web, non aveva adottato misure tecniche e organizzative idonee a prevenire il rischio di trattamenti illeciti, soprattutto nei casi in cui la registrazione e il rapporto contrattuale non si fossero perfezionati" — it had not adopted technical and organisational measures suitable to prevent the risk of unlawful processing, above all in cases where the registration and the contractual relationship had not been completed.

The mechanic is the part worth pinning to your own architecture: "anche quando gli utenti decidevano di non confermare la creazione dell'account, e dunque di non iscriversi al sito, Altroconsumo considerava comunque perfezionato il rapporto contrattuale." Even when users decided not to confirm account creation, and therefore not to register, the company still considered the contractual relationship concluded.

A second, separate violation was found: "mancata adozione di misure idonee a garantire l'effettivo esercizio dei diritti degli utenti e a fornire riscontro alle loro richieste senza ingiustificato ritardo" — failure to adopt measures ensuring users could actually exercise their rights and get a response without undue delay. Two failures, one root cause: the system had no state for "this person said no."

The order matters as much as the fine. The Garante "ha ordinato ad Altroconsumo di cessare il trattamento dei dati di coloro che non hanno confermato la creazione del proprio account e di adeguare le procedure di trattamento dei dati al GDPR" — stop processing the data of everyone who did not confirm their account, and bring its data-processing procedures into line with the GDPR.

The newsletter does not spell out which specific GDPR articles the authority formally pinned this on, and we are not going to guess. What we can say is that the mechanic it describes — treating an unformed contract as formed, then marketing on the strength of it — is precisely the stretch the EDPB says Article 6(1)(b) does not permit at paragraphs 28 and 47.

Altroconsumo was not the only company named that week. Two days earlier, on 27 July 2026, the Garante fined Lusha Systems Inc. €2,000,000 over contact-data enrichment, holding that "the pursuit of the legittimo interesse did not provide an adequate legal basis" and ordering both a processing ban and erasure of Italian residents' data. Legitimate interest had a bad week in Rome.

Does an Abandoned Cart Count as a Contract Under GDPR?

No. An abandoned cart is not a concluded contract, and treating it as one is the error the Garante fined. It may qualify as pre-contractual steps taken at the data subject's request under Article 6(1)(b) — but only for processing objectively necessary to those steps, which EDPB Guidelines 2/2019 paragraph 47 says excludes unsolicited marketing.

So "abandoned cart email" is not one legal question but two, split by which side of the request line the action falls on.

There is a further trap in the same guidance. Paragraph 41 of Guidelines 2/2019 addresses what happens when a contract ends: "as a general rule, the processing of that data will no longer be necessary for the performance of that contract and thus the controller will need to stop processing … it is generally unfair to swap to a new legal basis when the original basis ceases to exist." If your justification for holding a lead was "we are mid-transaction," you cannot quietly relabel it "legitimate interest" once the transaction dies.

And if your recovery email is personalised from browsing behaviour, paragraph 51 is worth reading before you rely on contract at all: contractual necessity "is not a suitable legal ground for building a profile of the user's tastes and lifestyle choices based on his clickstream on a website and the items purchased," because the controller "has not been contracted to carry out profiling."

The Distinction That Decides Your Case

Most guidance on this topic collapses every abandonment into one bucket. The Altroconsumo decision rewards operators who separate them. Here is the split that matters:

SituationWhat the person didStrongest available basisRecovery email?
Abandoned checkout, logged-in customerStarted a purchase you were asked to processArt. 6(1)(b) for the transaction; consent or Art. 6(1)(f) for marketingTransactional follow-up defensible; promotional content needs its own basis
Abandoned cart, known email, no confirmationAdded items, gave an address in the flowArt. 6(1)(b) pre-contractual for the requested step onlyMarketing needs consent or a documented Art. 6(1)(f) balancing test
Registration started, confirmation link never clickedDeclined the final stepNone for marketingNo — this is the Altroconsumo fact pattern
Newsletter form submitted, double opt-in not completedDeclined the final stepNone for marketingNo
Browse abandonment, no address givenNothing that identifies themn/aNo

Rows three and four are the ones people get wrong. In both, the user was shown a door and declined to walk through it — and in both, the record left behind looks exactly like a lead.

How to Fix an Abandoned-Signup Flow: Six Steps

  1. Find the unconfirmed records. Query your email platform and store database for records where a confirmation timestamp is null. In most stacks nobody has run this query, and the count surprises.
  2. Suppress them from every promotional flow immediately. Not just the welcome sequence: any segment defined by "has email address" silently includes them.
  3. Give unconfirmed records their own lifecycle. Set a short, documented deletion window — the record exists to let someone finish confirming, so it stops having a purpose when that window closes. This is the same differentiated-retention discipline described in our guide to GDPR retention policy for blocked and inactive data.
  4. Make double opt-in the default for form-captured addresses. It is the only design that produces the "deliberate action" EDPB Guidelines 05/2020 paragraph 77 requires, and it produces the audit trail at the same time.
  5. Record the evidence, not just the flag. Article 7(1) requires that "the controller shall be able to demonstrate that the data subject has consented," and EDPB Guidelines 05/2020 paragraph 104 confirms "the burden of proof will be on the controller." A boolean column is not proof — see our guide to proof of consent records.
  6. Close the rights loop. Altroconsumo's second violation was slow, ineffective handling of user requests. One intake channel, one owner, one clock: our guide to automating data subject access requests covers the mechanics.

If you only do one of these this quarter, do step one. You cannot fix a population you have not counted.

Common Mistakes, Ranked

1. Treating an incomplete signup as a completed one. The worst mistake, because it is invisible until a regulator asks. Altroconsumo's registration procedure had no state representing refusal.

2. Relying on legitimate interest without ever running the balancing test. Recital 47 permits direct marketing as a legitimate interest and then conditions it on reasonable expectations. An untested assertion of legitimate interest is not a basis, it is a hope. Write the assessment down.

3. Swapping legal basis when the first one runs out. Explicitly called out as generally unfair at paragraph 41 of EDPB Guidelines 2/2019. If contract was your basis and the contract never formed, there is no basis to fall back to.

4. Assuming the UK soft opt-in is broader than it is. PECR Regulation 22(3) requires all three limbs together: the details were obtained "in the course of the sale or negotiations for the sale of a product or service to that recipient", the direct marketing is "in respect of that person's similar products and services only", and a simple means of refusal was offered at collection and in every message since. An unconfirmed newsletter signup fails the first limb.

5. Treating consent as permanent. EDPB Guidelines 05/2020 paragraph 110 notes there is "no specific time limit in the GDPR for how long consent will last," and that consent obtained for one processing operation stops being valid if the operations "change or evolve considerably." Paragraph 111 recommends refreshing consent at appropriate intervals as best practice.

How PrivacyForge Helps

The recurring failure in this case is architectural, not editorial: an unconfirmed record and a confirmed subscriber looked the same to the system.

PrivacyForge's consent management stores each consent event with its timestamp, the exact wording shown, the capture method, and the source — the evidence Article 7(1) asks for, rather than a flag asserting that a yes happened once. Retention policies let unconfirmed signups carry a shorter, documented lifecycle than customers, which is the differentiation the Garante found missing. On the second violation, the DSAR workflow tracks each request against its statutory deadline, so "without undue delay" becomes a measured fact rather than an intention.

None of this substitutes for deciding your lawful basis. It makes the decision auditable once you have made it.

Frequently Asked Questions

Are abandoned cart emails GDPR compliant?

They can be, but not automatically. A purely transactional follow-up to a checkout the customer asked you to process may rest on Article 6(1)(b). Promotional content needs its own basis — consent, or legitimate interests with a documented balancing test — plus compliance with ePrivacy rules such as UK PECR Regulation 22 for the send itself.

Can I email someone who did not complete registration?

Not for marketing. This is the exact fact pattern the Italian Garante fined €280,000 on 29 July 2026: the company treated the contractual relationship as concluded even where users declined to confirm account creation. An unconfirmed registration signals refusal, and EDPB Guidelines 2/2019 paragraph 47 states the pre-contractual basis does not cover unsolicited marketing.

Does an abandoned cart count as a contract under GDPR?

No. An abandoned cart is not a concluded contract. It may qualify as pre-contractual steps taken at the data subject's request under Article 6(1)(b), but only for processing objectively necessary to the steps actually requested. EDPB Guidelines 2/2019 paragraph 22 sets that test as "objectively necessary", which excludes marketing added on the controller's own initiative.

Is legitimate interest enough for cart-recovery email?

Sometimes, but only with a documented balancing test. Recital 47 accepts that direct marketing may be a legitimate interest, while conditioning it on the reasonable expectations of the data subject and warning that rights override the controller where people do not reasonably expect further processing. Someone who declined to confirm has signalled the opposite expectation.

Does GDPR require double opt-in?

GDPR does not name double opt-in as a requirement. It requires a clear affirmative act and that you be able to demonstrate consent under Article 7(1). Double opt-in is the most reliable design for producing both, which is why it is the practical answer to a confirmation-abandonment problem even though no article mandates it.

How long can I keep the data of someone who never confirmed?

Only as long as the confirmation purpose lasts. Once your confirmation window closes, the record has no purpose and should be deleted. The Garante ordered Altroconsumo to cease processing the data of everyone who had not confirmed their account, which makes deletion the expected remedy rather than indefinite retention in a suppressed segment.

Conclusion

The lesson of the €280,000 fine is not that recovery email is illegal. It is that your database needs a state for "no."

Most stacks model completion and nothing else, so someone who stopped halfway becomes indistinguishable from someone who finished, and every downstream flow inherits an assumption nobody made deliberately. Fix that state model and the legal-basis question resolves itself in most rows; leave it unfixed and no amount of unsubscribe-link polish will help.

Start with the query in step one: how many records in your system have a null confirmation timestamp and an active marketing subscription? For a broader picture of where this obligation sits, see our complete guide to GDPR compliance.

This is informational content, not legal advice. Decisions about lawful basis for your own marketing should be taken with qualified advice on your specific facts.

Sources