Fino

Garante per la protezione dei dati personali (Italy) · 17 April 2026

Poste Italiane S.p.a. · PostePay S.p.a.

The source names these parties without saying which one the decision is about. I’m checking it.

About: Accountability, DPIA, Data principles, Data security, Transparency, Unlawful processing

Fine€12,501,000Violation found
Regulator
Garante per la protezione dei dati personali (Italy)
Decided
17 April 2026
Country
Italy
Sector
Not given
Regulator’s reference
10241537
Fino case number
2026/IT/122
Export as PDF

What happened

The DPA fined the Italian Post and PostePay a total of €12,501,000 for multiple infringements relating to the processing of personal data for the detection of malware from the devices of users who installed the controllers’ applications.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • DPIA
  • Data principles
  • Data security
  • Transparency
  • Unlawful processing

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/IT/122.