Ambrosetti S.p.A. – €85,000 Fine (Italy, 2026)

€85,000Garante per la protezione dei dati personali17 April 2026Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Ambrosetti S.p.A. was fined for not informing people about a data breach in time. This is important because it shows that companies must quickly notify users when their data is at risk.

What happened

Ambrosetti S.p.A. failed to inform users about a data breach within the required timeframe.

Who was affected

Approximately 62,000 individuals whose contact details and login credentials were compromised were affected.

What the authority found

The authority found that Ambrosetti S.p.A. violated GDPR by not notifying affected individuals promptly after a data breach.

Why this matters

This case underscores the importance of timely communication with users about data breaches. Companies should have clear procedures for notifying users to avoid penalties.

GDPR Articles Cited

AI-verified

Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)
Art. 5(1)(e) GDPR
Art. 5(1)(f) GDPR
View original scraped data
Art. 5(1)(e) GDPR
Art. 5(1)(f) GDPR
Art. 32(GDPR)
Art. 33(GDPR)
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 27 May 2026
scope corrected
Full Legal Summary
Detailed

Ambrosetti S.p.A. (the controller) is a consulting company. In 2024 the controller informed the DPA of a data breach, in accordance with Article 33 GDPR. The controller estimated that the data breach could have affected around 134,000 data subjects (later lowered to approximately 62,000), and concerned their contact details and login credentials. In addition, the controller stated that it was unlikely that the data breach posed a high risk for data subjects, since the credential data was the initial registration credentials set by the controller and not the user. Finally, the controller stated that it had hired external staff to develop a large number of their systems, and it had assumed that the system security was also monitored by the external staff. During its investigations, the DPA found that some of the passwords in question appeared to be set by the data subjects and not the controller. The controller did not initially inform the affected data subjects, but later contacted data subjects it had an email address on file. The controller also published a notice on its website and contacted news outlets. The DPA found a violation of Article 34 GDPR, as the controller failed to inform data subjects within the time limit, and had failed to justify the delay. The DPA considered that the data breach was likely to pose a high risk to the rights and freedoms of data subjects, and therefore, the controller had the obligation to inform them. The DPA took into consideration data subjects’ tendency to reuse passwords, the high number of affected data subjects, and the fact that the controller did not inform the data subjects until the DPA ordered it to do so during its investigations. The DPA also found a violation of Article 5(1)(e) GDPR, as the controller had failed to comply with the principles of storage limitation. The DPA found that the controller retained authentication credentials when it was no longer needed (e.g. certain systems that were no longer in use). T

Related Enforcement Actions (0)

No other enforcement actions found for Ambrosetti S.p.A. in IT

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

17 April 2026

Authority

Garante per la protezione dei dati personali

Fine Amount

€85,000

GDPRhub ID

gdprhub-10020

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Ambrosetti S.p.A. - Italy (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: