Poste Italiane S.p.a. – €12,501,000 Fine (Italy, 2026)

€12,501,000Garante per la protezione dei dati personali17 April 2026Italy
final
ePrivacy
Fine

Poste Italiane was fined over 12 million euros for improperly accessing and processing users' personal data without proper consent. This case shows that companies must follow strict rules when handling personal data, especially regarding user consent. It serves as a warning to businesses about the serious consequences of violating data protection laws.

What happened

Poste Italiane unlawfully accessed and processed personal data on users' devices for antifraud measures without proper consent.

Who was affected

Users whose personal data was accessed and processed by Poste Italiane.

What the authority found

The authority found that Poste Italiane violated multiple GDPR rules related to data processing and user consent.

Why this matters

This significant fine illustrates the heavy penalties companies can face for failing to comply with data protection regulations. It highlights the need for businesses to ensure they have valid consent before processing personal data.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(e) GDPR
Art. 6(1)(f) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)
Art. 6(1)(f) GDPR
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 122 Italian Code transposing Article 5(3) e-Privacy Directive 2002/58

Entities Involved

Poste Italiane S.p.a.
PostePay S.p.a.
Source verified 28 April 2026
articles corrected
national law identified
amount discrepancy
entity split needed
scope corrected
date discrepancy
Full Legal Summary
Detailed

The case involves unlawful access and processing of personal data on users' devices for antifraud measures, not directly related to cookie consent or tracking issues.

Violations (2)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Misleading Banner Messaging
critical

The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).

Art. 7 GDPR

Details

Fine Date

17 April 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€12,501,000

GDPRhub ID

gdprhub-9958

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Poste Italiane S.p.a. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: