Garante per la protezione dei dati personali (Italy) · 17 April 2026
Poste Italiane S.p.a. · PostePay S.p.a.
The source names these parties without saying which one the decision is about. I’m checking it.
About: Accountability, DPIA, Data principles, Data security, Transparency, Unlawful processing
- Regulator
- Garante per la protezione dei dati personali (Italy)
- Decided
- 17 April 2026
- Country
- Italy
- Sector
- Not given
- Regulator’s reference
- 10241537
- Fino case number
- 2026/IT/122
What happened
The DPA fined the Italian Post and PostePay a total of €12,501,000 for multiple infringements relating to the processing of personal data for the detection of malware from the devices of users who installed the controllers’ applications.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a) · 5(1)(e)Read →
- Art. 6Lawfulness of processing6(1)(f)Read →
- Art. 13Information to be provided where personal data are collected from the data subjectRead →
- Art. 25Data protection by design and by defaultRead →
- Art. 32Security of processingRead →
- Art. 35Data protection impact assessmentRead →
- Accountability
- DPIA
- Data principles
- Data security
- Transparency
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/122.