Poste Italiane S.p.a. – €12,501,000 Fine (Italy, 2026)

€12,501,000Garante per la protezione dei dati personali17 April 2026Italy
final
ePrivacy
Fine

Poste Italiane was fined over 12 million euros for misleading users about how it used their data and for not getting proper consent for third-party cookies. This case shows that companies must be clear and honest about data usage and obtain consent before tracking users. It emphasizes the need for transparency in online practices.

What happened

Poste Italiane processed user data and used third-party cookies without obtaining proper consent.

Who was affected

Users of Poste Italiane's services whose data was processed without proper consent.

What the authority found

The authority found that Poste Italiane violated several GDPR rules, including misleading users and failing to obtain consent for data processing.

Why this matters

This significant fine serves as a warning to companies about the importance of clear communication and consent regarding data usage. Businesses should review their cookie policies and ensure they comply with consent requirements.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)
Art. 5(1)(a) GDPR
Art. 5(1)(e) GDPR
Art. 6(1)(f) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)
Art. 6(1)(f) GDPR
Art. 13(GDPR)
Art. 25(GDPR)
Art. 32(GDPR)
Art. 35(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 122 Italian Code transposing Article 5(3) e-Privacy Directive 2002/58

Entities Involved

Poste Italiane S.p.a.
PostePay S.p.a.
Source verified 28 April 2026
articles corrected
national law identified
amount discrepancy
entity split needed
scope corrected
date discrepancy
Full Legal Summary
Detailed

The case involves unauthorized access and processing of device data for security purposes, unrelated to cookies or consent mechanisms.

Violations (2)

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Misleading Banner Messaging
critical

The cookie banner uses misleading language to trick or pressure users into accepting cookies (dark patterns).

Art. 7 GDPR

Details

Fine Date

17 April 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€12,501,000

GDPRhub ID

gdprhub-9958

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Poste Italiane S.p.a. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: