Intesa Sanpaolo S.p.A. – €31,800,000 Fine (Italy, 2026)

€31,800,000Garante per la protezione dei dati personali26 March 2026Italy
final
ePrivacy
Fine

Intesa Sanpaolo S.p.A. was fined €31.8 million for a data breach caused by an employee's unauthorized access. This case is crucial as it underscores the need for strict internal controls to protect sensitive customer information.

What happened

Intesa Sanpaolo S.p.A. experienced a data breach due to unauthorized access by an employee.

Who was affected

Customers whose personal data was exposed during the data breach at Intesa Sanpaolo S.p.A.

What the authority found

The Italian authority determined that Intesa Sanpaolo failed to implement adequate security measures to protect personal data, violating GDPR requirements.

Why this matters

This ruling serves as a strong reminder for financial institutions and other companies to enforce robust internal security protocols to safeguard customer data.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 8 April 2026
scope corrected
Full Legal Summary
Detailed

The case involved a data breach due to unauthorized access by an employee, unrelated to cookies or consent mechanisms.

Details

Fine Date

26 March 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€31,800,000

GDPRhub ID

gdprhub-9916

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Intesa Sanpaolo S.p.A. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: