Intesa Sanpaolo SpA – €100,000 Fine (Italy, 2022)

€100,000Garante per la protezione dei dati personali26 May 2022Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Intesa Sanpaolo SpA, an Italian bank, shared a customer's account information with her father without her permission. This breach of privacy matters because it shows that companies must handle personal data carefully and respect individuals' rights. The bank was found to have acted unlawfully in this situation.

What happened

Intesa Sanpaolo SpA disclosed a customer's account data to her father without her consent.

Who was affected

The customer whose account information was shared without her permission.

What the authority found

The Italian data protection authority ruled that the bank had no legal basis for processing the customer's data, violating GDPR's principles of lawful processing.

Why this matters

This case highlights the importance of obtaining proper consent before sharing personal information. Companies must ensure they have valid reasons for processing personal data to avoid legal issues.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 77(GDPR)
Art. 58(2) GDPR
Art. 85(3) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 5(1)(f) GDPR
Art. 6(GDPR)
Art. 58(2) GDPR
Art. 77(GDPR)
Art. 85(3) GDPR

Original data from scraper before AI verification against source document.

Source verified 3 April 2026
articles corrected
national law identified
Full Legal Summary
Detailed

The controller is Intesa Sanpaolo SpA, a bank in Italy. The data subject is a customer of the bank. The controller communicated the data subject's current account data to her father while she was already of age. The data was disclosed in a pending judgment in the Tribunale di Bari. The documents were meant for limited disclosure. The data subject lodged a complaint with the Italian DPA for unlawful processing of her personal data by the controller, consisting of communication to unauthorized third parties (her father). The controller justified the incident by invoking the good faith of its employee, as the data subject's father was previously authorized to access her account data, exercising parental authority until she reached the age of majority. Furthermore, her father was a former employee of the controller. This previously existing relationship had led the employee to believe he was still authorized to access the accounting data. Thus, the bank had acted in good faith. The DPA stated that there was no legal basis for processing the data subject's account data. The DPA therefore held that the processing in question was unlawful, as it was carried out in violation of the general principles pursuant to Article 5(1)(a) and (f) and Article 6 GDPR. Contrary to what was argued by the controller, the DPA found the exemption of good faith not applicable. Good faith can only exclude liability when it is unavoidable. In the present case, the employee should have checked whether the data subject's father was still authorized to access her account details. The DPA issued a €100,000 fine for these violations.

Related Enforcement Actions (0)

No other enforcement actions found for Intesa Sanpaolo SpA in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

26 May 2022

Authority

Garante per la protezione dei dati personali

Fine Amount

€100,000

GDPRhub ID

gdprhub-5060

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Intesa Sanpaolo SpA - Italy (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: