Italian Data Protection Authority (Garante) · 10 July 2025
Poste Vita S.p.a.
Insufficient technical and organisational measures to ensure information security
Fine€80,000Fine issued
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 10 July 2025
- Country
- Italy
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2025/IT/049
What happened
The DPA fined an insurance provider €80,000 for unlawfully disclosing a policyholder’s personal data to an impersonator and for failing to notify the data breach in time to the DPA.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2025/IT/049.