UniCredit S.p.A. – €2,800,000 Fine (Italy, 2024)

€2,800,000Garante per la protezione dei dati personali8 February 2024Italy
final
ePrivacy
Fine

UniCredit S.p.A. was fined for a data breach caused by vulnerabilities in its mobile banking portal. This is crucial because it shows that financial institutions must secure their systems to protect customers' personal data. Companies should regularly check their security measures to prevent breaches.

What happened

UniCredit S.p.A. experienced a data breach due to security vulnerabilities in its mobile banking portal.

Who was affected

Customers of UniCredit who used the mobile banking portal were affected.

What the authority found

The authority ruled that UniCredit violated GDPR articles related to data security and breach notification.

Why this matters

This case underscores the importance of robust security measures in financial services. Other companies should prioritize cybersecurity to safeguard user data.

GDPR Articles Cited

AI-verified

Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
articles corrected
Full Legal Summary
Detailed

The case involves a data breach due to vulnerabilities in a mobile banking portal, not related to cookies or consent.

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

8 February 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€2,800,000

GDPRhub ID

gdprhub-7707

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. UniCredit S.p.A. - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: