Italian Data Protection Authority (Garante) · 14 July 2026
NIER Ingegneria S.p.A. SB
Insufficient technical and organisational measures to ensure information security
- Regulator
- Italian Data Protection Authority (Garante)
- Decided
- 14 July 2026
- Country
- Italy
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2026/IT/103
What happened
The Italian DPA has imposed a fine of EUR 120,000 on NIER Ingeneriegna S.p.A. SB. NIER is a consultancy firm offering engineering, sustainability and software services. The controller informed the authority about a data breach caused by a ransomware attack. The affected data concerned the personal data of employees and employees of clients of the firm, in total around 500 data subjects were affected. The attackers used stolen credentials to access the internal network via a VPN. The controller failed to implement adequate security measures, such as multi-factor authentication and blocking certain credentials from accessing the network.
Summary from the CMS Enforcement Tracker, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(f)Read →
- Art. 32Security of processingRead →
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/103.