Intesa Sanpaolo S.p.A. – €31,800,000 Fine (Italy, 2026)

€31,800,000Garante per la protezione dei dati personali26 March 2026Italy
final
ePrivacy
Fine

Intesa Sanpaolo S.p.A. was fined for a serious data breach that allowed unauthorized access to banking data. This case underscores the importance of strong data protection measures for financial institutions.

What happened

Intesa Sanpaolo S.p.A. experienced a data breach involving unauthorized access to banking data.

Who was affected

Customers whose banking data was compromised in the breach.

What the authority found

The authority found that Intesa Sanpaolo S.p.A. failed to protect personal data adequately, violating GDPR requirements.

Why this matters

This case highlights the critical need for financial companies to implement robust security measures to protect customer data. It serves as a warning that breaches can lead to significant penalties.

GDPR Articles Cited

AI-verified

Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 5(2) GDPR
Art. 24(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 8 April 2026
scope corrected
Full Legal Summary
Detailed

The case is about a data breach involving unauthorized access to banking data, with no mention of cookie or consent banner violations.

Details

Fine Date

26 March 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€31,800,000

GDPRhub ID

gdprhub-9916

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Intesa Sanpaolo S.p.A. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: