Intesa Sanpaolo S.p.A. – €31,800,000 Fine (Italy, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Intesa Sanpaolo S.p.A. was fined €31.8 million for a serious data breach that exposed banking data without proper security measures. This incident highlights the critical importance of protecting sensitive customer information, especially in the banking sector.
What happened
Intesa Sanpaolo suffered a data breach that allowed unauthorized access to sensitive banking data.
Who was affected
Customers whose banking information was compromised during the data breach.
What the authority found
The Italian data authority found that Intesa Sanpaolo failed to implement adequate security measures to protect personal data, violating GDPR requirements.
Why this matters
This hefty fine underscores the need for businesses to prioritize data security and compliance with GDPR to avoid severe financial penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
Intesa Sanpaolo S.p.A. (the controller) is a bank. In 2024, the controller reported a data breach to the DPA in accordance with Article 33 GDPR. According to the controller, the data breach occurred between 2022 and 2024, as a result of an employee accessing the banking data of nine data subjects without authorisation. The controller also stated that it would inform the affected data subjects, despite claiming that it had not identified any high risks to their rights and freedoms. The DPA began an ex-officio investigation after the press reported a much higher number of data subjects affected than the controller had claimed (over 3,500). The controller argued that the fact that a data breach occurred did not mean its security measures were insufficient. In addition, it argued that there was no need to inform all affected data subjects, as the data breach did not pose a high risk for their rights and freedoms. During its investigations, the DPA concluded that the data breach likely posed a high risk for the affected data subjects, and ordered the controller to notify all affected data subjects. In response, the controller informed the DPA of the different measures taken to inform data subjects and to ensure security of processing. Specifically, it informed the DPA that it had decided not to contact approximately 1,300 data subjects, as it considered that the employee had accessed their data for purely service related reasons. The DPA considered that its order had not been complied with. The DPA found a violation of Articles 5(1)(f), 24 and 32 GDPR. During its investigations, the DPA found that the employee involved had full access to the financial data of all data subjects, and that the controller’s alert system did not detect any anomalies in the two year period the employee accessed data subjects’ data for non-service related reasons. Therefore, the controller had failed to implement appropriate security measures and had not complied with the principle of data se
Related Enforcement Actions (1)
Other enforcement actions involving Intesa Sanpaolo S.p.A. in IT
Details
Fine Date
26 March 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€31,800,000
GDPRhub ID
gdprhub-9916About this data
Cite as: Cookie Fines. Intesa Sanpaolo S.p.A. - Italy (2026). Retrieved from cookiefines.eu
Last updated: