Garante per la protezione dei dati personali (Italy) · 17 April 2026
Ambrosetti S.p.A.
About: Data breach, Data principles, Data security
Fine€85,000Violation found
- Regulator
- Garante per la protezione dei dati personali (Italy)
- Decided
- 17 April 2026
- Country
- Italy
- Sector
- Not given
- Regulator’s reference
- 280/2026
- Fino case number
- 2026/IT/110
What happened
The DPA fined a consulting company €85,000 for failing to ensure security of processing in relation to a data breach. In addition, the company did not inform the affected data subjects until ordered to do so by the DPA.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(e) · 5(1)(f)Read →
- Art. 32Security of processingRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Art. 34Communication of a personal data breach to the data subjectRead →
- Data breach
- Data principles
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/110.