Fino

Garante per la protezione dei dati personali (Italy) · 10 June 2020

Unicredit S.p.A.

About: Data security

Fine€600,000Violation found
Regulator
Garante per la protezione dei dati personali (Italy)
Decided
10 June 2020
Country
Italy
Sector
Not given
Regulator’s reference
9429195
Fino case number
2020/IT/051
Export as PDF

What happened

The Italian DPA imposed a fine of 600.000€ on a bank, Unicredit S.p.A. for two data breaches that it suffered between April 2016 and July 2017, which exposed common and financial data of 762.000 customers. The Data controller did not process personal data in a manner that ensured appropriate security of personal data, namely protection against unauthorised processing from a third party, and it did not follow the specific guidelines established for the banking industry regarding the log tracking.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/IT/051.