Intesa Sanpaolo S.p.A. – €31,800,000 Fine (Italy, 2026)

€31,800,000Garante per la protezione dei dati personali26 March 2026Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Intesa Sanpaolo S.p.A. was fined €31.8 million for a serious data breach that exposed banking data without proper security measures. This incident highlights the critical importance of protecting sensitive customer information, especially in the banking sector.

What happened

Intesa Sanpaolo suffered a data breach that allowed unauthorized access to sensitive banking data.

Who was affected

Customers whose banking information was compromised during the data breach.

What the authority found

The Italian data authority found that Intesa Sanpaolo failed to implement adequate security measures to protect personal data, violating GDPR requirements.

Why this matters

This hefty fine underscores the need for businesses to prioritize data security and compliance with GDPR to avoid severe financial penalties.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 8 April 2026
scope corrected
Full Legal Summary
Detailed

Intesa Sanpaolo S.p.A. (the controller) is a bank. In 2024, the controller reported a data breach to the DPA in accordance with Article 33 GDPR. According to the controller, the data breach occurred between 2022 and 2024, as a result of an employee accessing the banking data of nine data subjects without authorisation. The controller also stated that it would inform the affected data subjects, despite claiming that it had not identified any high risks to their rights and freedoms. The DPA began an ex-officio investigation after the press reported a much higher number of data subjects affected than the controller had claimed (over 3,500). The controller argued that the fact that a data breach occurred did not mean its security measures were insufficient. In addition, it argued that there was no need to inform all affected data subjects, as the data breach did not pose a high risk for their rights and freedoms. During its investigations, the DPA concluded that the data breach likely posed a high risk for the affected data subjects, and ordered the controller to notify all affected data subjects. In response, the controller informed the DPA of the different measures taken to inform data subjects and to ensure security of processing. Specifically, it informed the DPA that it had decided not to contact approximately 1,300 data subjects, as it considered that the employee had accessed their data for purely service related reasons. The DPA considered that its order had not been complied with. The DPA found a violation of Articles 5(1)(f), 24 and 32 GDPR. During its investigations, the DPA found that the employee involved had full access to the financial data of all data subjects, and that the controller’s alert system did not detect any anomalies in the two year period the employee accessed data subjects’ data for non-service related reasons. Therefore, the controller had failed to implement appropriate security measures and had not complied with the principle of data se

Details

Fine Date

26 March 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€31,800,000

GDPRhub ID

gdprhub-9916

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Intesa Sanpaolo S.p.A. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: