Poste Italiane S.p.a. – €12,501,000 Fine (Italy, 2026)

€12,501,000Garante per la protezione dei dati personali17 April 2026Italy
final
ePrivacy
Fine

Poste Italiane was fined over 12 million euros for mishandling personal data by using misleading cookie banners and tracking users without consent. This is significant because it shows that companies must be clear and honest about how they collect and use data from users.

What happened

Poste Italiane used misleading cookie banners and tracked users without obtaining proper consent.

Who was affected

Website visitors who interacted with Poste Italiane's online services were affected by the unauthorized data tracking.

What the authority found

The Garante found that Poste Italiane violated several GDPR principles, including transparency and consent requirements.

Why this matters

This case sets a strong precedent for enforcing transparency in data collection practices. Companies should ensure their cookie banners are clear and comply with consent laws.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(e) GDPR
Art. 6(1)(f) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)
Art. 6(1)(f) GDPR
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 122 Italian Code transposing Article 5(3) e-Privacy Directive 2002/58

Entities Involved

Poste Italiane S.p.a.
PostePay S.p.a.
Source verified 28 April 2026
articles corrected
national law identified
amount discrepancy
entity split needed
scope corrected
date discrepancy
Full Legal Summary
Detailed

The case involves unauthorized access to device data for security purposes, unrelated to cookies or consent mechanisms.

Violations (2)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Misleading Banner Messaging
critical

The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).

Art. 7 GDPR

Details

Fine Date

17 April 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€12,501,000

GDPRhub ID

gdprhub-9958

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Poste Italiane S.p.a. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: