Fino

Italian Data Protection Authority (Garante) · 4 July 2024

Postel S.p.A

Insufficient technical and organisational measures to ensure information security

Fine€900,000Fine issued
Regulator
Italian Data Protection Authority (Garante)
Decided
4 July 2024
Country
Italy
Sector
Not given
Regulator’s reference
Not recorded
Fino case number
2024/IT/015
Export as PDF

What happened

The DPA fined a subsidiary of Poste Italiane €900,000 after a data breach led to the disclosure of employees' data. The controller did not resolve two vulnerabilities in its IT system, even though they had been known for almost a year.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Data breach
  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/IT/015.