Fino

Italian Data Protection Authority (Garante) · 8 February 2024

UniCredit S.p.a.

Insufficient technical and organisational measures to ensure information security

What happened next. Confirmed in court: the Milan Tribunal rejected UniCredit's challenge (judgment 4499/2026 of 28 July 2026). Source →

Fine€2,800,000Confirmed in court
Regulator
Italian Data Protection Authority (Garante)
Decided
8 February 2024
Country
Italy
Sector
Finance, Insurance and Consulting
Regulator’s reference
Not recorded
Fino case number
2024/IT/053
Export as PDF

What happened

The DPA fined a controller € 2.8 million for making personal data available in responses to all authentication attempts, including unsuccessful ones, and failing to prevent customer use of simple PINs.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2024/IT/053.