Intesa Sanpaolo SpA – €100,000 Fine (Italy, 2022)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Intesa Sanpaolo SpA, an Italian bank, shared a customer's account information with her father without her permission. This breach of privacy matters because it shows that companies must handle personal data carefully and respect individuals' rights. The bank was found to have acted unlawfully in this situation.
What happened
Intesa Sanpaolo SpA disclosed a customer's account data to her father without her consent.
Who was affected
The customer whose account information was shared without her permission.
What the authority found
The Italian data protection authority ruled that the bank had no legal basis for processing the customer's data, violating GDPR's principles of lawful processing.
Why this matters
This case highlights the importance of obtaining proper consent before sharing personal information. Companies must ensure they have valid reasons for processing personal data to avoid legal issues.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The controller is Intesa Sanpaolo SpA, a bank in Italy. The data subject is a customer of the bank. The controller communicated the data subject's current account data to her father while she was already of age. The data was disclosed in a pending judgment in the Tribunale di Bari. The documents were meant for limited disclosure. The data subject lodged a complaint with the Italian DPA for unlawful processing of her personal data by the controller, consisting of communication to unauthorized third parties (her father). The controller justified the incident by invoking the good faith of its employee, as the data subject's father was previously authorized to access her account data, exercising parental authority until she reached the age of majority. Furthermore, her father was a former employee of the controller. This previously existing relationship had led the employee to believe he was still authorized to access the accounting data. Thus, the bank had acted in good faith. The DPA stated that there was no legal basis for processing the data subject's account data. The DPA therefore held that the processing in question was unlawful, as it was carried out in violation of the general principles pursuant to Article 5(1)(a) and (f) and Article 6 GDPR. Contrary to what was argued by the controller, the DPA found the exemption of good faith not applicable. Good faith can only exclude liability when it is unavoidable. In the present case, the employee should have checked whether the data subject's father was still authorized to access her account details. The DPA issued a €100,000 fine for these violations.
Related Enforcement Actions (0)
No other enforcement actions found for Intesa Sanpaolo SpA in IT
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
26 May 2022
Authority
Garante per la protezione dei dati personali
Fine Amount
€100,000
GDPRhub ID
gdprhub-5060About this data
Cite as: Cookie Fines. Intesa Sanpaolo SpA - Italy (2022). Retrieved from cookiefines.eu
Last updated: