Poste Italiane S.p.a. – €12,501,000 Fine (Italy, 2026)
Poste Italiane was fined over 12 million euros for mishandling personal data by using misleading cookie banners and tracking users without consent. This is significant because it shows that companies must be clear and honest about how they collect and use data from users.
What happened
Poste Italiane used misleading cookie banners and tracked users without obtaining proper consent.
Who was affected
Website visitors who interacted with Poste Italiane's online services were affected by the unauthorized data tracking.
What the authority found
The Garante found that Poste Italiane violated several GDPR principles, including transparency and consent requirements.
Why this matters
This case sets a strong precedent for enforcing transparency in data collection practices. Companies should ensure their cookie banners are clear and comply with consent laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
Entities Involved
The case involves unauthorized access to device data for security purposes, unrelated to cookies or consent mechanisms.
Violations (2)
Third-party tracking cookies or scripts are loaded without obtaining prior user consent.
Art. 13, 14 GDPR
The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).
Art. 7 GDPR
Related Enforcement Actions (2)
Other enforcement actions involving Poste Italiane S.p.a. in IT
Fine
€12.5M
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
17 April 2026
Authority
Garante per la protezione dei dati personali
Fine Amount
€12,501,000
GDPRhub ID
gdprhub-9958About this data
Cite as: Cookie Fines. Poste Italiane S.p.a. - Italy (2026). Retrieved from cookiefines.eu
Last updated: