Intesa Sanpaolo S.p.A. – €31,800,000 Fine (Italy, 2026)

€31,800,000Garante per la protezione dei dati personali26 March 2026Italy
final
ePrivacy
Fine

Intesa Sanpaolo S.p.A. was fined for a data breach where an employee accessed sensitive banking information without permission. This is significant because it shows that companies must protect personal data and restrict access to authorized personnel only. Small businesses should review their security measures to prevent unauthorized access.

What happened

Intesa Sanpaolo S.p.A. faced a fine due to an employee accessing banking data without authorization, leading to a data breach.

Who was affected

Customers whose banking data was accessed without their consent by an unauthorized employee.

What the authority found

The Garante per la protezione dei dati personali found that Intesa Sanpaolo failed to adequately protect personal data, violating GDPR requirements.

Why this matters

This ruling highlights the need for strong data protection measures in companies. Businesses should ensure that only authorized personnel have access to sensitive information.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 8 April 2026
scope corrected
Full Legal Summary
Detailed

The case involves a data breach where an employee accessed banking data without authorization, leading to a high risk for affected data subjects.

Details

Fine Date

26 March 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€31,800,000

GDPRhub ID

gdprhub-9916

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Intesa Sanpaolo S.p.A. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: