Italian Data Protection Authority (Garante) · 26 March 2026
Intesa Sanpaolo S.p.A.
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 26 March 2026
- Country
- Italy
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/047
What happened
The DPA fined a bank €31,800,000 for not implementing sufficient safeguards to prevent an employee from accessing the financial data of over 3,500 data subjects for non-service related purposes. The controller also failed to inform the DPA and the affected data subjects about the data breach on time.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 24Responsibility of the controllerRead →
- Art. 32Security of processingRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Accountability
- Data breach
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/047.