Garante per la protezione dei dati personali (Italy) - 10234984
| Garante per la protezione dei dati personali - 10234984 | |
|---|---|
| Authority: | Garante per la protezione dei dati personali (Italy) |
| Jurisdiction: | Italy |
| Relevant Law: | Article 5(1)(f) GDPR Article 5(2) GDPR Article 24 GDPR Article 32 GDPR Article 33 GDPR Article 34 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 10.10.2024 |
| Decided: | 26.03.2026 |
| Published: | 26.03.2026 |
| Fine: | 31,800,000 EUR |
| Parties: | Intesa Sanpaolo S.p.A. |
| National Case Number/Name: | 10234984 |
| European Case Law Identifier: | n/a |
| Appeal: | n/a |
| Original Language(s): | Italian |
| Original Source: | GPDP (in IT) |
| Initial Contributor: | ap |
The DPA fined a bank €31,800,000 for not implementing sufficient safeguards to prevent an employee from accessing the financial data of over 3,500 data subjects for non-service related purposes. The controller also failed to inform the DPA and the affected data subjects about the data breach on time.
English Summary
Facts
Intesa Sanpaolo S.p.A. (the controller) is a bank. In 2024, the controller reported a data breach to the DPA in accordance with Article 33 GDPR. According to the controller, the data breach occurred between 2022 and 2024, as a result of an employee accessing the banking data of nine data subjects without authorisation. The controller also stated that it would inform the affected data subjects, despite claiming that it had not identified any high risks to their rights and freedoms.
The DPA began an ex-officio investigation after the press reported a much higher number of data subjects affected than the controller had claimed (over 3,500). The controller argued that the fact that a data breach occurred did not mean its security measures were insufficient. In addition, it argued that there was no need to inform all affected data subjects, as the data breach did not pose a high risk for their rights and freedoms.
During its investigations, the DPA concluded that the data breach likely posed a high risk for the affected data subjects, and ordered the controller to notify all affected data subjects. In response, the controller informed the DPA of the different measures taken to inform data subjects and to ensure security of processing. Specifically, it informed the DPA that it had decided not to contact approximately 1,300 data subjects, as it considered that the employee had accessed their data for purely service related reasons. The DPA considered that its order had not been complied with.
Holding
The DPA found a violation of Articles 5(1)(f), 24 and 32 GDPR. During its investigations, the DPA found that the employee involved had full access to the financial data of all data subjects, and that the controller’s alert system did not detect any anomalies in the two year period the employee accessed data subjects’ data for non-service related reasons. Therefore, the controller had failed to implement appropriate security measures and had not complied with the principle of data security or accountability. This was especially relevant considering the fact that the controller processed financial data of “high risk customers“ (public or political figures).
The DPA also found a violation of Article 33 GDPR. The DPA considered that the controller had not followed the notification obligations following a data breach, as it had provided incomplete information that was supplemented much later (following press reports and the DPA’s investigation). In addition, the DPA stated that the controller had incorrectly applied ENISA Guidelines.
Finally, the DPA found a violation of Article 34 GDPR. The DPA noted that the controller had only notified data subjects after being ordered to do so by the DPA. In addition, the controller had failed to inform all affected data subjects. Nonetheless, the DPA acknowledged that the controller had taken measures to strengthen safeguards.
The DPA found a violation of Articles 5(1)(f) and (2), 24, 32, 33, and 34 GDPR, and fined the controller €31,800,000. The DPA took into consideration the high number of data subjects affected (including public figures), as well as the delay from the controller’s part in notifying the data breach after being aware of it.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.
SEE ALSO
- Press release of March 30, 2026
- Provision of November 2, 2024
- Press release of November 5, 2024
[web doc. no. 10234984]
Provision of March 26, 2026
Register of Provisions
No. 208 of March 26, 2026
THE ITALIAN DATA PROTECTION AUTHORITY
IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice-President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;
SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016;
HAVING SEEN, in particular, Articles 33 and 34 of the Regulation, entitled, respectively, "Notification of a personal data breach to the supervisory authority" and "Communication of a personal data breach to the data subject";
HAVING SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018);
HAVING REGARD to the "Guidelines 9/2022 on the Notification of Personal Data Breach under the GDPR" adopted by the European Data Protection Board on March 28, 2023, replacing the "Guidelines on the Notification of Personal Data Breach under Regulation (EU) 2016/679" of the Article 29 Data Protection Working Party of October 3, 2017, as amended and lastly adopted on February 6, 2018, and endorsed by the European Data Protection Board on May 25, 2018 (hereinafter the "Notification Guidelines");
HAVING REGARD to the "Guidelines 01/2021 on examples of personal data breach notification" adopted by the European Data Protection Board on December 14, 2021 (hereinafter the "Guidelines on Personal Data Breach Cases");
HAVING REGARD to Decision No. 192 of May 12, 2011, as amended, containing "Provisions on the circulation of information in the banking sector and the tracking of banking transactions," published in the Official Journal (G.U.) No. 127 of June 3, 2011 (available on the Authority's website at: https://www.gpdp.it, web doc. No. 1813953);
HAVING EXAMINED the documentation in the file;
HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Authority's Regulation No. 1/2000;
REPORTER: Professor Pasquale Stanzione;
WHEREAS
1. Introduction
On July 17, 2024, Intesa Sanpaolo S.p.A. (hereinafter, ISP or the Bank) submitted to the Authority, pursuant to Article 33 of Regulation (EU) 2016/679 (hereinafter, GDPR), a breach notification was issued following the unauthorized access by a Bank employee working at the Agribusiness branch in Barletta to the bank data of several customers "...without professional motivation."
In this context, the Bank stated that the breach occurred between February 21, 2022, and April 24, 2024, and that such access "...involved customers (including their mother and other acquaintances/relatives), current and former employees of the Bank," for a total of nine data subjects. It also stated that it became aware of the incident during periodic "...second-level checks regarding potential anomalies in employee access to bank data, detected by the alert systems adopted."
In the aforementioned notification, ISP stated that, "...while not detecting any significant risks to the rights and freedoms of individuals, [...] in order to provide all relevant information regarding the incident and to allow for a prompt response to any requests for further clarification, it will inform the nine interested parties (including acquaintances and relatives of the employee involved) who were the subject of the highest number of accesses, through a meeting conducted by the heads of the branches where the relationships are established."
Subsequently, with a supplementary notification dated August 30, 2024, ISP deemed it necessary to clarify that, following disciplinary proceedings initiated against the employee, it had ordered his dismissal, for just cause, on August 7, 2024.
2. The preliminary investigation.
Following press reports in early October 2024, which reported that a Bank employee had access, outside of the proper scope of his duties, to banking information relating to a significant number of customers, the Office initiated a complex and detailed investigation. This investigation revealed that the scope of the breach reported to the Authority by the Bank with the aforementioned notifications was much broader than previously assumed.
2.2. The request for information dated October 10, 2024.
In order to obtain information useful for assessing the personal data protection aspects related to the incident, the Office sent the Bank a specific request for information, pursuant to art. 157 of the Code (see note prot. no. 118325 of October 10, 2024), to which ISP responded on October 17, 2024, stating that:
- the personal data breach event described in the notification of July 17, 2024, was the same as that reported in the press reports;
- the breach consisted of "...loss of confidentiality, due solely to access by an employee that was apparently not justified by business reasons";
- the Bank became aware, for the first time, of an anomalous access by the employee on October 9, 2023, following the activation of an alert as part of the controls implemented by ISP, in compliance with Provision no. 192 regarding "Requirements regarding the circulation of information in the banking sector and the tracking of banking transactions," adopted by the Authority on May 12, 2011;
- the alert reported a potential anomaly regarding the employee's query of a customer's credit card transactions for the previous two months;
- on July 4, 2024, following the activation of other alerts at a later date and the outcome of internal checks, including analysis of the employee's access logs, retained for 24 months pursuant to the aforementioned Order No. 192/2011, the Bank initiated disciplinary proceedings against the employee;
- the number of data subjects involved was, at this time, "...undetermined – that is, determining it with reasonable certainty would require a disproportionate effort. The number of 3,572 customers reported in the press, corresponding to 6,637 accesses made by the Employee and indicated in the Audit function report dated May 21, 2024 [...], corresponds to customers not based at the Agribusiness Branch in Barletta and the related branches in Bisceglie and Ruvo di Puglia (Branch and branches pertaining to the Employee) whose data was accessed by the Employee on 460 days between February 21, 2022, and April 24, 2024."
- "...the inquiries made by the employee during the two-year analysis period on 3,572 customers could, theoretically, be consistent with the specific operations of an Agribusiness Manager (the position held by the employee), who may be required to conduct "circular" inquiries even from customers not established at their own branch...". In this regard, "...the employee challenged the legitimacy of some of the 6,637 accesses...";
- the Audit Report revealed that, with reference to the clients accessed by the employee: "...34 are national politicians, belonging to both center-right and center-left political forces. In total, in the two-year analysis period, the Employee made 102 inquiries relating to these individuals (equal to 1.54% of the total 6,637 accesses cited in the Audit Report). In particular, for 15 of the 34 politicians, the Employee made only one inquiry and, for another 11 individuals, he made two. Of the 34 politicians, 10 were found to have no existing relationship with the Bank at the time of the events (with a blank ballot); 43 are nationally renowned figures from the world of entertainment, sports, and news; 73 are employees and managers of the Bank, including some senior figures; the remaining 3,422 clients consist, predominantly, of individuals from the Employee's place of residence or rooted in other places that revolve around his personal sphere and professional. Specifically, approximately 2,450 of these individuals are located in Bari and surrounding areas of the Employee's municipality of residence. The accesses involved 1) contractual/SICLI positions (NJ00 - customer record), 2) account movements (IY11 - e/c for internal use) and payment cards (ZAFI - allows querying the "payment cards" world), sometimes including transaction details, and 3) financial assets (DAPY - investments).
- The Bank stated that it had no evidence of the data being accessed by its employee being extracted from internal information systems.
- The Bank reiterated that it had not communicated the data to the interested parties, pursuant to art. 34 of the Regulation, since, "in line with the conclusions of the Data Protection Officer, the Bank (data controller) did not consider the personal data breach in question to be 'likely to result in a high risk to the rights and freedoms of natural persons' (Article 34.1 GDPR) and, therefore, failed to communicate the personal data breach to all potentially affected individuals";
- the Bank was, however, "...considering sending our entire customer base, consisting of approximately 13 million data subjects, a client care communication describing how the incident actually unfolded and what its potential consequences might be, as well as the measures we have adopted and those we are considering adopting";
- with respect to what was described in the notification of 17 July 2024, the Bank wished to clarify that "...the notification filed on 17 July 2024 is only the first communication to the Authority on the matter of interest..." that, with reference to the indication of 9 interested parties involved, "certainly the positions of 9 of the Bank's customers (7 NDG5 + 2 joint account holders) were subject to anomalous accesses by the Employee given the number of such accesses" and that, furthermore, "these are, specifically, customers who were subject to a total of 1,333 accesses out of a total of 6,637 accesses extracted in the two-year analysis period for the purposes of the Bank's checks".
2.2. Order No. 659 of November 2, 2024, and subsequent requirements.
Pending the completion of a more extensive investigation, it was deemed necessary to verify the compliance of the initiatives undertaken by the Bank to protect data subjects following the breach, with particular reference to compliance with the reporting obligations pursuant to Article 34 of the GDPR towards data subjects whose data was accessed by the employee.
Following the investigations, the Guarantor, contrary to the Bank's view, determined that the breach of the data subjects' personal data was likely to pose a high risk to their rights and freedoms. Therefore, with Order No. 659 of November 2, 2024 (web doc. No. 10070521), it ordered the Bank to communicate, pursuant to Articles 34, paragraph 4, and 58, paragraph 1, of the GDPR. 2, letter e), of the GDPR, the breach was communicated to all data subjects whose personal and banking data had been accessed and could not be traced back, with certainty, to the employee's ordinary work activity, demonstrating to the Authority that they had complied with the requirements set forth in the aforementioned Order.
With a note dated December 5, 2024 (ref. no. 143598), the Bank provided further clarifications regarding the matter and disclosed the steps taken to inform users affected by the personal data breach.
In particular, it highlighted that:
- as a correction to the previous statement, "...the total number of customers (NDG) involved amounts to 3,572. For the purposes of defining the scope and subsequent communication, the employee's mother was also included, resulting in a total of 3,573 customers (NDG)";
- "Regarding the accesses involving 1,648 customers (NDG), no evidence has emerged to date that would allow them to be unequivocally linked to the Employee's ordinary work activity. Therefore, in compliance with the Order, the Bank has issued individual notification."
- "Regarding the accounts of 1,328 customers (NDG), the Employee did not perform any queries aimed at viewing banking data along with personal data. Specifically, the documentation shows that, for these accounts, the Employee viewed only the first four screens of the NJ00 application. These first screens contain only internal Bank identification codes and common customer personal data (name, surname, place and date of birth, tax code) [...] the Bank believes that the accesses in question fall squarely within the category of accesses motivated by service reasons, as they are typical of a Business/Agribusiness manager performing his or her duties."
- "With regard to 597 customers (NDG), the Employee accessed not only the personal data contained in the NJ00 file, but also banking data (such as transaction balances and cards). However, these queries affected: 486 customers (NDG) who are legal entities, excluded from the scope of the GDPR; 83 customers (NDG) directly connected to the Employee's management portfolio (e.g., a shareholder in a company included in the portfolio), and therefore clearly fulfilling service-related reasons; 26 customers (NDG) who are now deceased and therefore excluded from the scope of communication pursuant to Article 34 GDPR2; 2 customers (NDG) who are no longer reachable due to a lack of contact details in their database";
- "...the Bank immediately initiated the communication process for 597 customers, prioritizing the overall cluster of customers for whom individual communication was necessary. These 597 customers were in fact identified as being at greater risk based on the analyses conducted...";
- "Regarding two interested parties, who hold high-ranking government officials, [...] the communication, out of due institutional respect, was made directly by the Bank's top management;
- In total, the communication process involved "...1,645 affected customers (NDG), including the 597 customers identified for the first phase of communication via the Digital Branch";
- "Specifically, the methods adopted for communication to the 1,645 customers are as follows: 1,144 customers (NDG) via Online Reporting (ROL), both via the app and via Internet Banking; the communication was visible to customers from November 21; 385 customers (NDG) via registered mail; for technical reasons, the letters were delivered to Poste Italiane in batches, the largest of which were delivered on November 21-22; 116 customers (NDG) via Online Reporting and registered mail";
- "For communications via Online Reporting (ROL), a further initiative has been launched to draw customers' attention to the communication. Specifically, starting November 27, a pop-up has been introduced on both the App and Internet Banking channels."
- "Intesa Sanpaolo has decided to immediately further strengthen the measures in place to protect the confidentiality of its customers' personal and banking data," specifically through "strengthening ex-ante controls applicable to all individual customers, through: Introduction, starting November 4, of a pop-up solution on the manager's desktop for the most sensitive procedures, as an ex-ante filter requiring the Manager to justify the reason for accessing information relating to customers outside their portfolio, with subsequent tracking and transmission to the Branch Manager and Control Functions for their compliance; Based on the pop-up, introduction, starting November 18, of an ex-ante authorization system: i. Activation of a confirmation prompt for circular information requests where the Customer is present in the branch (e.g., via a digital authorization form to be signed by the Customer); ii. Introduction of a digital authorization process for the Branch Manager to authorize the Manager to query requests made where the Customer is not present."
- It was also planned to "strengthen ex-post control activities on potential anomalous access through enhanced alert systems, such as: Activation of new alerts starting October 28 to monitor anomalous queries on a number of customers outside the Manager's portfolio, both "standard" customers and Politically Exposed Persons (PEPs); Activation of a task force starting November 4 dedicated to analyzing the results of the new alerts and supporting the decision-making and authorization process";
- Finally, "an initial list of 18 Sensitive Customers with an Institutional Profile ("SEC") was introduced on an experimental basis starting October 21, extended on November 19 to 623 SEC Customers, for whom enhanced ringfencing mechanisms were established."
After examining the information received, the Office sent a further request for clarification to the Bank, believing that the latter—with regard to the 1,328 customers for which it had decided not to submit the communication pursuant to art. 34 of the GDPR - had not correctly interpreted the provisions of Order No. 659 of November 2, 2024.
Specifically, with a note dated December 12, 2024 (ref. No. 146264), the Bank was asked to:
- provide complete feedback regarding the communications, including those to the 1,328 customers to whom the Bank had decided not to provide any communications;
- specify the methods of communication to the interested parties, via Online Reporting (ROL), App, and Internet Banking, also indicating the measures adopted to document the receipt and reading of the communication;
- specify whether, with reference to the sole proprietorships whose personal and banking data were subject to unauthorized access by the employee, communication was made pursuant to Art. 34 of the GDPR.
In a letter dated December 19, 2024 (ref. no. 149833), ISP provided feedback, noting:
- that it had sent the communication, pursuant to Article 34 of the GDPR, to the 1,328 customers previously excluded;
- that with respect to the previous point, excluding the 29 uncontactable customers and the 27 deceased, "communications were […] sent to 1,272 customers (NDG), broken down as follows: 476 customers (NDG) received the communication via Online Reporting (ROL), both via the app and via Internet Banking; the communication was visible to customers starting December 19th; 776 customers (NDG) received it via registered mail; on December 18th, the communications were delivered to the external supplier for printing and enveloping; as for the delivery of letters to Poste Italiane, this is expected to take place by December 19th in the majority of cases;
- "with regard to the methods for sending the communication, […] the criterion of preference expressed by the customer in the contractual context was followed, so those who opted for online reporting methods received the communications pursuant to art. 34 GDPR in digital form";
- "for customers enabled for the My Key remote banking service, a special notice (banner) has been made visible in bold, bold color (orange) and the wording "Important communication" and then "Notice of access to your personal data" on both the App and Internet Banking channels, indicating the presence of an important communication in the Archive section [...] This banner remains visible at every login and internal navigation until the customer clicks the "Read" button on the banner and, after the pop-up opens, also clicks the "I understand" button on the same pop-up. The pop-up can be closed by clicking the "X"; However, this closure is not equivalent to clicking the "I understand" button and therefore results in the banner being displayed again upon each subsequent access";
- "With regard to sole proprietorships whose personal and banking data were subject to unauthorized access, we confirm that, based on the checks carried out, the former employee accessed a total of 170 customers (NDG). Communications pursuant to Article 34 of the GDPR were sent to all these customers..."
On January 14, 2025 (ref. no. 4137), a further request for clarification was addressed to the Bank regarding the communications sent to interested parties via the App. The Bank responded to this request with a note dated January 24, 2025 (ref. no. 9754).
3. Initiation of the proceedings and integration of the investigation.
Taking into account the assessments carried out by the Authority's Digital Technologies and Cybersecurity Department, contained in a technical report prepared on March 3, 2025 (ref. no. 27544), the statements made by the parties, as well as the information acquired during the investigation, the Office, with a note dated May 27, 2025 (ref. no. 72300), following the investigations into the management of the data breach, notified the Bank, pursuant to art. 166, paragraph 5 of the Code, the initiation of proceedings to ascertain the alleged violations of Articles 5, paragraph 1, letter f), and paragraphs 2, 24, 32, 33, and 34 of the GDPR.
With a communication dated June 20, 2025 (ref. no. 88917), the Bank requested an extension of the deadline for submitting its defense briefs, which the Authority granted with a letter dated June 24, 2025 (ref. no. 89371).
On July 10, 2025 (file no. 98694), the Bank submitted its written submissions, arguing that:
- the inadequacy of the security measures adopted by the data controller cannot be inferred solely from the fact that a personal data breach has actually occurred, since the GDPR is intended to limit the risks of personal data breaches, not to eliminate them. The Court of Justice expressed this view in its ruling in Case C340/21, which stated that "Articles 24 and 32 of the GDPR must be interpreted as meaning that […] unauthorized access to such data by third parties pursuant to Article 4.10 of that regulation is not sufficient, in itself, to conclude that the technical and organizational measures implemented by the data controller were not adequate within the meaning of Articles 24 and 32." Therefore, the adequacy of the measures adopted by the data controller must be assessed on a case-by-case basis, "taking into account the risks associated with the processing in question and assessing whether the nature, content, and implementation of such measures are appropriate to those risks." Furthermore, in this specific case, given that the breach involved only access without data exfiltration by the employee, it appears to be "one of the most difficult to prevent," potentially confounding legitimate access operations due to the employee's duties.
- It cannot be demonstrated that the measures adopted were inadequate to prevent the data breach, to the extent possible. What is currently evident, however, is the lack of evidence of actual harm suffered by the data subjects and that the security measures adopted by the Bank "allowed the data breach to be intercepted."
- The security measures adopted by the Bank prior to the data breach already included measures such as employee training policies, an authorization system based on employee roles and duties, a logging system "designed to meet the requirements of Provision 192" adopted by the Authority in 2011, and an alerting and control system "created to identify potentially anomalous behavior related to consultations conducted by the Bank's operators."
- The Bank's alerting system had been strengthened and updated prior to the data breach and following measures already adopted by the Authority against the Bank (Provisions No. 270 of May 27, 2021, and No. 272 of July 28, 2022).
- The employee's conduct—difficult to predict, identify, and neutralize—emerged "precisely thanks to internal alerts," which, in line with Provision 192, were not immediately apparent. 192/2011 of the Authority, "allowed the activation of the additional levels of control and mitigation measures envisaged";
- the criteria used by the Bank to assess the severity of the data breach, particularly with regard to the execution of the so-called override (reclassification), contrary to what the Authority claims, were objective, given the lack of discretion in identifying these criteria, based on the ENISA methodology (also recommended by the EDPB "Notification Guidelines"); the absence of previous privacy alerts due to the employee's conduct; the cooperation and statements of the same employee; and the absence, to date, of evidence of the exfiltration of personal data as a result of the data breach;
- Regarding the alleged violation of the accountability principle, the latter does not require the data controller to conduct assessments that are "completely correct, nor does it require the controller to avoid breaches of the obligations set forth in privacy legislation," but rather to "comply with the general principles governing the processing of personal data and to be able to demonstrate such compliance." To argue otherwise, "any violation of personal data protection legislation by the data controller [...] would automatically also result in a violation of the accountability principle," with the associated consequences, including in terms of sanctions.
- The above is confirmed, in particular, by the interpretation of the accountability principle made by the Authority on the dedicated page of its website (https://www.gpdp.it/regolamentoue/attacco-basato-sul-rischio-e-misure-di-accountability-responsabilizzazione-di-titolari-e-responsabili), according to which data controllers are required to notify violations, as required by Article 13 of the GDPR. 33 of the GDPR, "only if they consider it likely that such a breach will result in a risk to the rights and freedoms of data subjects (see Recital 85)", in light of which "notification of the breach to the Authority is not mandatory"; from the Technical Report of the competent Department, which "traced the [override] case to Article 24 of the GDPR (and not Article 5, paragraph 2 of the GDPR)";
- with regard to the alleged violation of Article 33 of the GDPR, it would have acted in good faith, with regard to the indication contained in the notification of July 17, 2024, of nine individuals involved in the data breach, having considered only those to whom the greatest number of accesses had been made; This choice is also supported by the principles set forth by the EDPB in its "Notification Guidelines," which specify that "the GDPR allows for approximations regarding the number of natural persons affected [...] the focus should be on addressing the negative effects of the breach rather than providing exact figures."
- the accesses made by the employee did not present any abnormalities that would be considered incompatible with the performance of normal work duties;
- subsequent investigations "confirmed that the information transmitted by the Bank to the Data Protection Authority on July 17, 2024, and subsequently supplemented on August 30, 2024, was already sufficient to provide a sufficiently clear and complete picture of the incident [...] to allow the Authority to assess the extent of the data breach."
- regarding the alleged violation of Article 13 of the GDPR, 34 of the GDPR, even if such a breach were deemed to have occurred, it would be "lacking in harmfulness, having not proven to be [...] prejudicial" in the absence of data exfiltration.
With reference to the assessment criteria set forth in Article 83 of the GDPR, the Bank stated that:
- regarding the breach of the accountability principle, it:
• "cannot be considered serious, as it did not have any consequences for the data subjects;
• was of very limited duration, as the Bank promptly took action to further strengthen its safeguards."
- regarding the aspects pertaining to the data breach, it was "a harmless breach:
• as it did not have any consequences for the data subjects;
• as it was of limited duration, involving a single personal data breach."
- regarding the intentional or negligent nature of the breach, given that "Intesa's operations are consistently guided by the principles of good faith and transparency, in accordance with the applicable regulatory framework [...] even in the case of the data breach, the Bank's approach was guided by a concrete desire to comply with the provisions of the Regulation and the national implementing legislation," therefore the Bank "could be solely attributable to [...circumstances] based on minor negligence," also considering that the "Bank promptly adopted concrete and structured initiatives to strengthen its organizational data protection capabilities, specifically with the launch of the Nemo Program";
- In relation to the measures adopted by the controller to mitigate the damage suffered by data subjects, the Bank, through the Nemo Program, has established a working group to address various areas, including, but not limited to:
a) "the introduction of enhanced protection mechanisms for certain individuals holding positions of particular relevance for the constitutional order and/or national security (SEC customer register);
b) the strengthening of the internal system of ex ante authorizations and ex post controls, through both organizational and technical interventions;
c) the introduction of a dynamic data masking solution for masking customer data on summary systems and governance areas";
- In relation to any previous relevant violations committed, the Bank stated that it was the recipient of two relevant provisions on the matter, No. 270 of May 27, 2021, and No. 272 of July 28, 2022. In this regard, the Bank clarified that "the data breach in question was detected [...] precisely thanks to the alert system implemented by the Bank and strengthened over time, also as a result of the aforementioned measures."
- regarding the level of cooperation with the Supervisory Authority, the Bank stated that it provided full cooperation "not only by providing the information and clarifications requested, but also by implementing the measures prescribed by the Guarantor and adopting additional technical and organizational measures."
- regarding the categories of personal data affected by the breach, the Bank confirmed that the accesses concerned ordinary personal data.
- regarding the additional elements required by Article 83 of the GDPR for the purpose of quantifying any potential fines, the Bank stated in particular that the breaches in question did not "result in any economic or financial benefits for Intesa. Quite the opposite."
4. The applicable regulatory framework.
Article 5(1)(f) of the GDPR, in identifying the principles applicable to processing, establishes that personal data must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures ('integrity and confidentiality')."
Article 5(2) and Article 24 of the GDPR then define the principle of accountability, which places the data controller's overall responsibility for implementing appropriate technical and organizational measures to ensure, and to be able to demonstrate, that processing complies with data protection legislation.
It follows that data controllers are responsible for independently deciding on the methods, safeguards, and limits of personal data processing, in compliance with regulatory provisions and in light of certain specific criteria set out in the GDPR.
Article 32 of the GDPR, concerning the security of processing, also establishes that "taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk [...]" and that "when assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed" (Article 32, paragraphs 1 and 2 of the GDPR).
Article 33, paragraph 1 of the GDPR further provides that "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."
The "Notification Guidelines" highlight in this regard that "depending on the nature of the breach, the controller may need to conduct further investigations to establish all the relevant facts relating to the incident [...]. This means that the Regulation acknowledges that the controller does not always have all the necessary information about a breach within 72 hours of becoming aware of it, as full and comprehensive details of an incident are not always available within that timeframe. Therefore, the Regulation allows for phased notification. This is more likely to be the case with more complex breaches, such as certain types of cybersecurity incidents, where, for example, an in-depth forensic investigation may be necessary to fully establish the nature of the breach and the extent of the personal data compromise. Consequently, in many cases the controller will need to conduct further investigations and follow up on the notification by providing additional information at a later stage" (paragraphs 56 and 57).
This also allows the supervisory authority to assess the adequacy of the decisions taken by the controller regarding communication to data subjects and the measures taken to address the breach.
Article 34 of the GDPR establishes that "where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay," that "the communication to the data subject shall […] describe in clear and plain language the nature of the personal data breach and contain at least the information and the measures referred to in points (b), (c), and (d) of Article 33(3)" and that such communication is not required, in particular, if "the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the breach, in particular those designed to render the personal data unintelligible to any person who is not authorized to access it, such as encryption."
The GDPR also states that risk assessment should take into account both the likelihood and severity of risks to the rights and freedoms of data subjects and that such risks should be determined based on an objective assessment (see recommendations 75 and 76).
In this regard, the aforementioned "Notification Guidelines" identify the following factors to be considered—in the event of a personal data breach—in assessing the risk to the rights and freedoms of data subjects: the type of breach; the nature, sensitivity, and volume of personal data; the ease of identification of data subjects; the severity of the consequences for data subjects; the specific characteristics of the data subject; the specific characteristics of the data controller; and the number of data subjects affected.
The "Notification Guidelines" themselves emphasize that: "the Regulation states that communication of a breach to data subjects should occur 'without undue delay,' which means as soon as possible," given that the primary purpose of communication to data subjects is to provide them with specific information on the measures they can take to protect themselves; the data controller, among the measures to be taken to remedy the breach and mitigate its possible negative effects for data subjects, "should also provide specific advice to natural persons on how to protect themselves from the possible negative consequences of the breach."
5. The outcome of the investigation and the procedure for adopting corrective measures and sanctions.
The investigation revealed that a Bank employee accessed the financial information of 3,573 customers for over two years, "between February 21, 2022, and April 24, 2024," without any need for it in relation to his duties. He accessed the information 6,637 times, without the alert systems detecting any anomalies.
Among these customers, a number were found to be individuals holding a role of public importance. This circumstance further aggravates the gravity of the facts, considering that the Bank also manages treasury and cash services for members of parliament and high-ranking institutional officials designated by the Bank as politically exposed persons (PEPs).
For this reason, the employee was subjected to disciplinary proceedings and imposed a sanction pursuant to Article 7 of Law No. 300/1970.
5.1 Violation of Article 5, paragraph 1, letter f) and paragraph 2, of Article 24 of the GDPR. The principle of accountability and the security of processing
In relation to the proceedings in question, it is particularly significant that the Bank adopted the organizational decision to allow designated operators (such as the employee responsible for the improper consultations) to query, "in full circularity," not only the data of customers operating at their respective branches, but also the entire customer base, thus allowing access to all customer data.
This organizational decision, which is subject to the Authority's unquestionable review, inevitably entails the need to counterbalance this broad freedom of action of individual operators and to adopt adequate measures to reduce the risk that inappropriate behavior by an individual employee could negatively impact, as in this case, the rights and freedoms of data subjects. These measures, which the data controller has not been able to demonstrate, have been adopted.
Given the Bank's business model, which is geared toward full circularity, adequate precautions and controls are not implemented for access by customers outside of the Bank's portfolio or without active accounts. These include, for example, requiring prior authorization from a supervisor, or allowing limited access to customer data from other branches.
In a context that is certainly considered high-risk, given the bank's banking activities, the controls adopted by the Bank were therefore deemed insufficient to meet the obligations set forth in Articles 5, 24, and 32 of the GDPR. Additional measures, designed to prevent, detect, and promptly report suspicious access, would have been necessary, even if formally compatible with the authorization profiles issued to employees.
Given that the Bank uses digitalization as a key enabling factor for optimizing internal processes, security, and an increasingly inclusive and integrated offering of banking services, it would certainly have been able and required to implement appropriate contextual verification mechanisms regarding the actual operational need for its operators to access data, such as mandatory linking to pending contractual relationships, the introduction of dynamic authorization limitation systems, automatic consistency checks between role and accessed data, or alerts related to specific customer types.
Also considering the presence of politically exposed persons (PEPs) among the customers affected by the employee's unauthorized access, it is clear that the Bank's use of exclusively quantitative thresholds, with extended temporal frequencies, proved to be an unsuitable and ineffective measure to detect illegitimate conduct characterized by repeated but time-distributed access, which presumably remained below the alert thresholds established by the ISP.
In particular, with specific reference to the category of high-risk customers (i.e., publicly or politically exposed), it would have been necessary to implement enhanced controls.
In such cases, in application of the risk-based approach principle, the Bank should have implemented dedicated and more stringent controls, lower alert thresholds, and more frequent monitoring, considering that greater public visibility can naturally increase the risk of access for purposes unrelated to the management of ordinary operations.
Furthermore, it would have been necessary to provide automatic escalation mechanisms in the event of access outside of the context of ordinary operations, through immediate notification to the operator's direct supervisor and timely verification by the Bank's control functions (compliance, privacy, and security).
The failure to differentiate controls based on the status of a public or politically exposed person highlights the lack of an adequate risk assessment, as well as the adoption of belated and fragmented control measures, in violation of Articles 5, paragraph 1, letter f), and 32 of the GDPR.
In relation to the objections raised by the Bank in its defense briefs, regarding the Authority's criticism of the incorrect assessment of the severity of the event classified by ISP as "medium risk" due to the alleged presence of certain risk-reducing factors (such as, for example: the absence of previous privacy alerts, due to the employee's conduct, towards individuals other than the data subjects or towards the same data subjects; the employee's cooperation; the employee's statements regarding not having made copies or not having shared the accessed data with anyone), it is emphasized that attributing the cause of the incident to an employee's conduct does not in itself reduce the severity of the consequences for the data subjects, nor the likelihood of misuse of the accessed data, which the preliminary investigation did not rule out.
5.2 Violation of Article 33 of the GDPR. Notification of the "data breach".
Pursuant to Recital 75 of the GDPR, the risk must be assessed exclusively in relation to the rights and freedoms of natural persons, taking into account material and non-material damage, risks of fraud, identity theft, reputational damage, and discrimination.
From this perspective, the "Notification Guidelines" reiterate that the risk assessment must be conducted based on the severity and likelihood of impacts on the rights and freedoms of data subjects, without attributing decisive importance to the cause or origin of the breach.
The recommendations developed by the European Union Agency for Network and Information Security (ENISA), cited in the aforementioned "Notification Guidelines," require a structured risk assessment based on objective parameters geared towards the effects on data subjects, including the nature, sensitivity, and volume of the data, the number of data subjects involved, the characteristics of the data subjects (vulnerability, public exposure, role), and the severity and likelihood of impacts.
In this case, the override was applied by the Bank to reduce the risk based on the internal cause of the incident, without evidence of objective factors that effectively reduced the impact or likelihood of harm to the data subjects.
The presence of publicly and politically exposed persons among those affected by the improper questioning is also difficult to reclassify the risk through an override to reduce its scope.
In essence, the Bank declared in the proceedings that it applied the ENISA methodology but substantially deviated from it without objective and verifiable justification.
In light of the elements examined, therefore, the Bank's conduct constitutes a violation of the principle of accountability pursuant to Articles 5, paragraph 2, and 24 of the GDPR, as the risk assessment was not consistent, objective, and demonstrable, nor aligned with the declared methodology.
With regard to the content and timing of the data controller's notification to the Data Protection Authority as required by Article 13 of the GDPR, 33 of the GDPR, it is established that, although the Bank formally declared the notification issued on July 17, 2024, to be "complete," it was found to be largely incomplete regarding the actual scope of the data breach and the number of data subjects involved. It was only partially supplemented on August 30, 2024, significantly late, compared to the deadlines required by Article 33 of the GDPR.
The true extent of what happened emerged exclusively following the evidence of the facts, resulting from the publication of press reports and the investigation initiated by the Guarantor itself, which finally made the full scope of the event clear.
The data controller's explanation, according to which "the data breach was characterized by the Bank as a loss of confidentiality, potentially resulting solely in the personal data of some of the Bank's customers being accessed by unauthorized third parties, therefore appears to fail to take into account the seriousness of this conduct. Over time, this assessment is validated by the absence of any known consequences beyond the temporary compromise of data confidentiality. It is therefore confirmed that the information transmitted by the Bank to the Data Protection Authority on July 17, 2024, and subsequently supplemented on August 30, 2024, was already sufficient to provide a sufficiently clear and complete picture of the incident, in light of that context, to allow the Authority to assess the extent of the data breach and, if deemed appropriate, to request additional information."
The Bank's failure to provide a complete, exhaustive, and timely account of the true extent of the breach seriously compromised the Authority's ability to adequately assess the facts and promptly exercise its powers of intervention and support, precluding (or at least significantly delaying) the adoption of adequate measures to mitigate the risks to data subjects, in violation of Article 33 of the GDPR.
5.3 Violation of Article 34 of the GDPR. Notification to data subjects.
Regarding notification to data subjects pursuant to Article 34 of the GDPR, the Authority, in Order No. 659, adopted on November 2, 2024, disagreeing with the Bank's assessments in this regard, deemed that the personal data breach in question was likely to pose a high risk to the rights and freedoms of natural persons, given the nature of the personal data breach—which, under the conditions set forth in Article 13 of the Italian Criminal Code, 615-ter, may constitute a criminal offense; the categories of personal data affected by the breach; the severity and persistence of the consequences for natural persons that could arise from the breach (such as, for example, disclosure of information regarding financial status, reputational damage); and the controller's business sector, which requires a high degree of accountability on the part of its authorized personnel to maintain customer trust, particularly by satisfying their legitimate expectations of confidentiality and security of processing.
The considerations reported by the Bank in its defense briefs demonstrate an inadequate understanding of the controller's obligations towards data subjects, thus negatively impacting their rights, especially considering that some of them are also politically exposed persons or otherwise persons of public notoriety.
From this perspective, the disclosure required by Article 34 of the GDPR constitutes a necessary risk mitigation measure and preventive protection of data subjects' rights, regardless of evidence of (possibly) already occurring damage.
The delay in providing the aforementioned notification, which occurred only following the Authority's injunction, and its incompleteness effectively limited the data subjects' ability to take timely mitigation measures and exercise their rights in a fully informed manner, thereby increasing their exposure to risk and failing to comply with the provisions of Article 34 of the GDPR.
In this context, however, it is noted that, following the data breach, the Bank took steps to strengthen its safeguards through the aforementioned "Nemo Program."
It is believed, in fact, that the introduction of enhanced protection mechanisms for the data of certain individuals holding particularly high-level positions (so-called "SEC" clients) and the strengthening of the internal system of ex ante authorizations and ex post controls will allow for a strengthened (and more effective) control system aimed at addressing and preventing, to the extent possible, the risks of unauthorized access.
At the same time, strengthening governance processes is also essential, particularly with regard to data breach management, enabling a prompt escalation procedure for managing unjustified access to customer data, particularly for the most exposed parties.
6 Conclusions: Verification of violations and declaration of unlawfulness of processing. Corrective measures pursuant to Article 58, paragraph 2, of the GDPR.
For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office with the initiation of the proceeding pursuant to Article 166, paragraph 5 of the Code and are therefore unsuitable for dismissing this proceeding, given that none of the cases provided for in Article 11 of the Garante's Regulation No. 1/2019 apply.
The unlawfulness of the conduct carried out by Intesa Sanpaolo S.p.A., as set out above, has therefore been established in relation to Articles 5, paragraph 1, letter f), and paragraph 2; 24; 32; 33 and 34 of the GDPR.
With regard to the exercise of the corrective powers referred to in Article 58, paragraph 2, of the Regulation, we acknowledge that Intesa Sanpaolo S.p.A. has complied with the requirements set forth in Order No. 659, adopted by the Garante on November 2, 2024, and that, during the proceedings, it has also spontaneously adopted certain measures, reported in this decision (see paragraph 3 above), aimed at aligning, in accordance with the regulatory framework described above, the processing of customer data with the GDPR, which are shared by the Authority.
Furthermore, it is stated that the conditions set forth in Article 17 of the aforementioned Regulation No. 1/2019 of the Italian Data Protection Authority are met.
7. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the GDPR; Article 166, paragraph 7, of the Code).
The Italian Data Protection Authority, pursuant to Article 58, paragraph 2, letter i) of the GDPR and Article 166 of the Code, has the power to impose an administrative pecuniary sanction pursuant to Article 83, paragraph 4, and paragraph 1, of the Italian Data Protection Authority. 5 of the GDPR, by issuing an injunction (Article 18 of Law No. 689 of 24 November 1981) in relation to the processing of personal data carried out by Intesa Sanpaolo S.p.A., which was found to be unlawful, as set out above.
The violation, found in accordance with the grounds set out in the reasoning, cannot be considered "minor," in light of the combined provisions of Recital 148 and Article 83 of the GDPR.
We believe it is appropriate to apply Article 83(3) of the GDPR, which provides that "if, in relation to the same or linked processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement." The total amount of the fine is calculated so as not to exceed the maximum fine set forth in the same Article 83(3). 5 of the GDPR.
With reference to the elements listed in Article 83, paragraph 2, of the GDPR, for the purposes of applying the administrative pecuniary sanction and its quantification, given that the sanction must "in any case be effective, proportionate, and dissuasive" (Article 83, paragraph 1, of the GDPR), it is noted that, in this case, the following circumstances were considered:
- the relevance of the nature of the violations, concerning the failure to comply with measures aimed at ensuring adequate security of personal data, the principle of accountability, and the proper management of obligations related to the data breach that occurred (Article 83, paragraph 2, letter a) of the GDPR); the large number of data subjects involved (approximately 3,500 customers); the duration of the violation (which lasted for over two years); and the consequences that the unlawful processing had on the legal status of the data subjects. In favor of the offender, however, the non-specific nature of the personal data being processed was taken into account (Article 83, paragraph 2, letter g) of the GDPR);
- with respect to the subjective element, the Bank's conduct was taken into account, whose procedural, organizational, and supervisory shortcomings allowed the offense to be materially committed by its employee (Article 83, paragraph 2, letter b) of the GDPR). Furthermore, for the purposes of assessing the sanction, the Bank's inadequate handling of the obligations required by Articles 33 and 34 of the Regulation regarding personal data breaches is also relevant. It emerged that the data breach notification occurred significantly later than the Bank became aware of it, and that, even after the complete notification was sent on August 30, 2024, the information provided to the Authority only provided a partial picture of the true extent of the breach;
- the adoption of measures aimed at mitigating the harm suffered by data subjects, which occurred belatedly and only in compliance with the provisions of Order No. 659, adopted by the Italian Data Protection Authority on November 2, 2024 (Article 83, paragraph 2, letter c) of the GDPR), resulting from an inadequate understanding of the data controller's obligations towards data subjects, thus negatively impacting their rights;
- the business decision to operate under a fully circular regime—which, by its nature, entails greater exposure to risks for customer data—without having previously adopted, in application of the principle of accountability, suitable measures to guarantee the security of such data, intervening instead only after the breach has occurred to contain its effects;
- there are previous relevant breaches committed by the Bank in its capacity as data controller and ascertained with the following orders: No. 270 of May 27, 2021 (web doc. no. 9718112); no. 272 of July 28, 2022 (web doc. no. 9812423); no. 202 of May 26, 2022 (web doc. no. 9784626) (Article 83, paragraph 2, letter e) of the GDPR); these precedents, although far less significant than the one addressed in this provision, should have prompted the Bank to review its internal procedures for securing data access by employees (which is possible, as evidenced by the measures adopted in paragraph 3), and its data breach management policies;
- Data controllers operating in the banking sector are required to fully implement the measures set forth in Provision no. 192 of 2011, in light of the current regulatory framework for the protection of personal data and technological developments. These factors would have required the Bank, in application of the principle of accountability, to progressively update and strengthen the measures adopted, also taking into account the concrete experience gained over time;
- the conduct of the Bank was taken into account, which, after the initiation of the proceedings, cooperated with the Authority (Article 83, paragraph 2, letter f) of the GDPR);
- the manner in which the Authority acquired full knowledge of the true extent of the violations, namely following press reports, given the lateness and incompleteness of the notifications sent by the Company (Article 83, paragraph 2, letter h) of the GDPR);
- With regard to any other aggravating or mitigating factors applicable to the circumstances of the specific case (Article 83, paragraph 2, letter k), the following mitigating factors were considered: the adoption of certain measures to align, in accordance with the regulatory framework described above, the processing of customer data with the GDPR, as set out in this decision (see above, paragraph 3), as well as the costs incurred by the Bank to implement these measures.
Furthermore, it is believed that, in this case, taking into account the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the GDPR), the financial situation of the offender, as reflected in the financial statements for 2024, is relevant.
In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative fine of €31,800,000.00 (thirty-one million eight hundred thousand euros) on Intesa Sanpaolo S.p.A.
NOW WITH ALL THE FOREGOING, THE GUARANTOR
declares, pursuant to Articles 57, paragraph 1, letter b) and c) of the GDPR, f) of the GDPR, the unlawfulness of the processing carried out by Intesa Sanpaolo S.p.A., with registered office at Piazza San Carlo 156, 10121 Turin, VAT No. 11991500015, pursuant to Art. 143 of the Code, for violation of Articles 5, paragraph 1, letter f), and paragraphs 2, 24, 32, 33, and 34 of the GDPR.
ORDERS
Intesa Sanpaolo S.p.A., pursuant to Art. 58, paragraph 2, letter i) of the GDPR, to pay the sum of €31,800,000.00 (thirty-one million eight hundred thousand/00 euros) as an administrative fine for the violations indicated in this order.
ORDERS
pursuant to Art. 58, paragraph 2, letter i) of the GDPR, to the same Bank, to pay the sum of €31,800,000.00 (thirty-one million eight hundred thousand/00 euros) as an administrative fine for the violations indicated in this order, according to the methods indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981.
It is hereby stated that, pursuant to Article 166, paragraph 8 of the Code, the violator retains the right to settle the dispute by paying—again according to the methods indicated in the attachment—an amount equal to half of the fine imposed within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below;
ORDERING
- Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, the publication of the injunction order on the Italian Data Protection Authority's website;
- Pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Italian Data Protection Authority Regulation No. 1/2019, the publication of this provision on the Italian Data Protection Authority's website;
- Pursuant to Article 17 of Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2, of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation.
Pursuant to Article 78 of the GDPR, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, this decision may be challenged before the ordinary judicial authorities, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days of the date of notification of the decision, or sixty days if the appellant resides abroad.
Rome, March 26, 2026
THE PRESIDENT
Stanzione
THE REPORTER
Stanzione
THE SECRETARY GENERAL
Montuori
SEE ALSO
- Press release of March 30, 2026
- Decision of November 2, 2024
- Press release of November 5, 2024
[web doc. no. 10234984]
Measure of March 26, 2026
Register of Measures
No. 208 of March 26, 2026
THE ITALIAN DATA PROTECTION AUTHORITY
IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;
SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016;
SEEN in particular Articles 33 and 34 of the Regulation, entitled, respectively, "Notification of a personal data breach to the supervisory authority" and "Communication of a personal data breach to the data subject";
HAVING SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of 30 June 2003, as amended by Legislative Decree No. 101 of 10 August 2018);
HAVING SEEN the "Guidelines 9/2022 on the Notification of Personal Data Breach under the GDPR" adopted by the European Data Protection Board on 28 March 2023, replacing the "Guidelines on the Notification of Personal Data Breach under Regulation (EU) 2016/679" of the Article 29 Data Protection Working Party of 3 October 2017, as amended and lastly adopted on 6 February 2018 and endorsed by the European Data Protection Board on 25 May 2018 (hereinafter the "Notification Guidelines");
HAVING SEEN the "Guidelines 01/2021 on examples of personal data breach notification" adopted by the European Data Protection Board on December 14, 2021 (hereinafter the "Guidelines on personal data breach cases");
HAVING SEEN Order No. 192 of May 12, 2011, and subsequent amendments, containing "Requirements for the circulation of information in the banking sector and the tracking of banking transactions," published in the Official Journal No. 127 of June 3, 2011 (available on the Garante's website at: https://www.gpdp.it, web doc. No. 1813953);
HAVING EXAMINED the documentation in the file;
HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Garante's Regulation No. 1/2000;
RAPPORTEUR: Professor Pasquale Stanzione;
WHEREAS
1. Introduction
On July 17, 2024, Intesa Sanpaolo S.p.A. (hereinafter, ISP or the Bank) sent the Authority, pursuant to Article 33 of Regulation (EU) 2016/679 (hereinafter, GDPR), a breach notification resulting from the unauthorized access by a Bank employee working at the Agribusiness branch in Barletta to the banking data of several customers "...without professional motivations."
In this context, the Bank stated that the breach occurred between February 21, 2022, and April 24, 2024, and that these accesses "...involved customers (including the mother and other acquaintances/relatives), current and former employees of the Bank," for a total of nine data subjects. It also stated that it became aware of the incident during periodic "...second-level checks regarding potential anomalies in employee access to banking data detected by the alert systems adopted."
In the aforementioned notification, ISP stated that, "...although it does not detect any significant risks to the rights and freedoms of individuals, [...] in order to provide all relevant information regarding the incident and allow for a prompt response to any requests for further clarification, it will inform the nine data subjects (including acquaintances and relatives of the employee involved) who were subject to the highest number of accesses, through a meeting conducted by the Branch Managers where the relationships are established."
Subsequently, with a supplementary notification dated August 30, 2024, ISP deemed it necessary to clarify that, following disciplinary proceedings initiated against the employee, it had ordered his dismissal, for just cause, on August 7, 2024.
2. Investigative activity.
Following press reports that appeared in early October 2024, reporting that a Bank employee had access, outside of the proper scope of his job, to banking information relating to a significant number of customers, the Office initiated a complex and detailed investigation that revealed that the scope of the violation reported to the Authority by the Bank in the aforementioned notifications was much broader than previously assumed.
2.2. Request for information dated October 10, 2024.
In order to obtain information useful for assessing the personal data protection aspects related to the incident, the Office sent the Bank a specific request for information pursuant to Article 157 of the Code (see note prot. no. 118325 of October 10, 2024), to which ISP responded on October 17, 2024, stating that:
- the personal data breach event described in the notification of July 17, 2024, was the same as that reported in the press;
- the breach consisted of "...loss of confidentiality, due solely to access by an employee that was apparently unjustified for business reasons";
- The Bank became aware, for the first time, of an anomalous access by the employee on October 9, 2023, following the activation of an alert as part of the controls implemented by ISP, in compliance with Provision No. 192 regarding "Requirements regarding the circulation of information in the banking sector and the tracking of banking transactions," adopted by the Authority on May 12, 2011;
- The alert reported a potential anomaly regarding the employee's query of a customer's credit card transactions for the previous two months;
- On July 4, 2024, following the activation of other alerts at a later date and the outcome of internal controls, including analysis of the employee's overall access logs, retained for 24 months pursuant to the aforementioned Provision No. 192/2011, the Bank initiated disciplinary proceedings against the employee;
- the number of data subjects involved was, at this time, "...undetermined – that is, determining it with reasonable certainty would require a disproportionate effort. The number of 3,572 customers reported in the press, corresponding to 6,637 accesses made by the Employee and indicated in the Audit function report dated May 21, 2024 [...], corresponds to customers not based at the Agribusiness Branch in Barletta and the related branches in Bisceglie and Ruvo di Puglia (Branch and branches pertaining to the Employee) whose data was accessed by the Employee on 460 days between February 21, 2022, and April 24, 2024."
- "...the inquiries made by the employee during the two-year analysis period on 3,572 customers could, theoretically, be consistent with the specific operations of an Agribusiness Manager (the position held by the employee), who may be required to conduct "circular" inquiries even from customers not established at their own branch...". In this regard, "...the employee challenged the legitimacy of some of the 6,637 accesses...";
- the Audit Report revealed that, with reference to the clients accessed by the employee: "...34 are national politicians, belonging to both center-right and center-left political forces. In total, in the two-year analysis period, the Employee made 102 inquiries relating to these individuals (equal to 1.54% of the total 6,637 accesses cited in the Audit Report). In particular, for 15 of the 34 politicians, the Employee made only one inquiry and, for another 11 individuals, he made two. Of the 34 politicians, 10 were found to have no existing relationship with the Bank at the time of the events (with a blank ballot); 43 are nationally renowned figures from the world of entertainment, sports, and news; 73 are employees and managers of the Bank, including some senior figures; the remaining 3,422 clients consist, predominantly, of individuals from the Employee's place of residence or rooted in other places that revolve around his personal sphere and professional. Specifically, approximately 2,450 of these individuals are located in Bari and surrounding areas of the Employee's municipality of residence. The accesses involved 1) contractual/SICLI positions (NJ00 - customer record), 2) account movements (IY11 - e/c for internal use) and payment cards (ZAFI - allows querying the "payment cards" world), sometimes including transaction details, and 3) financial assets (DAPY - investments).
- The Bank stated that it had no evidence of the data being accessed by its employee being extracted from internal information systems.
- The Bank reiterated that it had not communicated the data to the interested parties, pursuant to art. 34 of the Regulation, since, "in line with the conclusions of the Data Protection Officer, the Bank (data controller) did not consider the personal data breach in question to be 'likely to result in a high risk to the rights and freedoms of natural persons' (Article 34.1 GDPR) and, therefore, failed to communicate the personal data breach to all potentially affected individuals";
- the Bank was, however, "...considering sending our entire customer base, consisting of approximately 13 million data subjects, a client care communication describing how the incident actually unfolded and what its potential consequences might be, as well as the measures we have adopted and those we are considering adopting";
- with respect to what was described in the notification of 17 July 2024, the Bank wished to clarify that "...the notification filed on 17 July 2024 is only the first communication to the Authority on the matter of interest..." that, with reference to the indication of 9 interested parties involved, "certainly the positions of 9 of the Bank's customers (7 NDG5 + 2 joint account holders) were subject to anomalous accesses by the Employee given the number of such accesses" and that, furthermore, "these are, specifically, customers who were subject to a total of 1,333 accesses out of a total of 6,637 accesses extracted in the two-year analysis period for the purposes of the Bank's checks".
2.2. Order No. 659 of November 2, 2024, and subsequent requirements.
Pending the completion of a more extensive investigation, it was deemed necessary to verify the compliance of the initiatives undertaken by the Bank to protect data subjects following the breach, with particular reference to compliance with the reporting obligations pursuant to Article 34 of the GDPR towards data subjects whose data was accessed by the employee.
Following the investigations, the Guarantor, contrary to the Bank's view, determined that the breach of the data subjects' personal data was likely to pose a high risk to their rights and freedoms. Therefore, with Order No. 659 of November 2, 2024 (web doc. No. 10070521), it ordered the Bank to communicate, pursuant to Articles 34, paragraph 4, and 58, paragraph 1, of the GDPR. 2, letter e), of the GDPR, the breach was communicated to all data subjects whose personal and banking data had been accessed and could not be traced back, with certainty, to the employee's ordinary work activity, demonstrating to the Authority that they had complied with the requirements set forth in the aforementioned Order.
With a note dated December 5, 2024 (ref. no. 143598), the Bank provided further clarifications regarding the matter and disclosed the steps taken to inform users affected by the personal data breach.
In particular, it highlighted that:
- as a correction to the previous statement, "...the total number of customers (NDG) involved amounts to 3,572. For the purposes of defining the scope and subsequent communication, the employee's mother was also included, resulting in a total of 3,573 customers (NDG)";
- "Regarding the accesses involving 1,648 customers (NDG), no evidence has emerged to date that would allow them to be unequivocally linked to the Employee's ordinary work activity. Therefore, in compliance with the Order, the Bank has issued individual notification."
- "Regarding the accounts of 1,328 customers (NDG), the Employee did not perform any queries aimed at viewing banking data along with personal data. Specifically, the documentation shows that, for these accounts, the Employee viewed only the first four screens of the NJ00 application. These first screens contain only internal Bank identification codes and common customer personal data (name, surname, place and date of birth, tax code) [...] the Bank believes that the accesses in question fall squarely within the category of accesses motivated by service reasons, as they are typical of a Business/Agribusiness manager performing his or her duties."
- "With regard to 597 customers (NDG), the Employee accessed not only the personal data contained in the NJ00 file, but also banking data (such as transaction balances and cards). However, these queries affected: 486 customers (NDG) who are legal entities, excluded from the scope of the GDPR; 83 customers (NDG) directly connected to the Employee's management portfolio (e.g., a shareholder in a company included in the portfolio), and therefore clearly fulfilling service-related reasons; 26 customers (NDG) who are now deceased and therefore excluded from the scope of communication pursuant to Article 34 GDPR2; 2 customers (NDG) who are no longer reachable due to a lack of contact details in their database";
- "...the Bank immediately initiated the communication process for 597 customers, prioritizing the overall cluster of customers for whom individual communication was necessary. These 597 customers were in fact identified as being at greater risk based on the analyses conducted...";
- "Regarding two interested parties, who hold high-ranking government officials, [...] the communication, out of due institutional respect, was made directly by the Bank's top management;
- In total, the communication process involved "...1,645 affected customers (NDG), including the 597 customers identified for the first phase of communication via the Digital Branch";
- "Specifically, the methods adopted for communication to the 1,645 customers are as follows: 1,144 customers (NDG) via Online Reporting (ROL), both via the app and via Internet Banking; the communication was visible to customers from November 21; 385 customers (NDG) via registered mail; for technical reasons, the letters were delivered to Poste Italiane in batches, the largest of which were delivered on November 21-22; 116 customers (NDG) via Online Reporting and registered mail";
- "For communications via Online Reporting (ROL), a further initiative has been launched to draw customers' attention to the communication. Specifically, starting November 27, a pop-up has been introduced on both the App and Internet Banking channels."
- "Intesa Sanpaolo has decided to immediately further strengthen the measures in place to protect the confidentiality of its customers' personal and banking data," specifically through "strengthening ex-ante controls applicable to all individual customers, through: Introduction, starting November 4, of a pop-up solution on the manager's desktop for the most sensitive procedures, as an ex-ante filter requiring the Manager to justify the reason for accessing information relating to customers outside their portfolio, with subsequent tracking and transmission to the Branch Manager and Control Functions for their compliance; Based on the pop-up, introduction, starting November 18, of an ex-ante authorization system: i. Activation of a confirmation prompt for circular information requests where the Customer is present in the branch (e.g., via a digital authorization form to be signed by the Customer); ii. Introduction of a digital authorization process for the Branch Manager to authorize the Manager to query requests made where the Customer is not present."
- It was also planned to "strengthen ex-post control activities on potential anomalous access through enhanced alert systems, such as: Activation of new alerts starting October 28 to monitor anomalous queries on a number of customers outside the Manager's portfolio, both "standard" customers and Politically Exposed Persons (PEPs); Activation of a task force starting November 4 dedicated to analyzing the results of the new alerts and supporting the decision-making and authorization process";
- Finally, "an initial list of 18 Sensitive Customers with an Institutional Profile ("SEC") was introduced on an experimental basis starting October 21, extended on November 19 to 623 SEC Customers, for whom enhanced ringfencing mechanisms were established."
After examining the information received, the Office sent a further request for clarification to the Bank, believing that the latter—with regard to the 1,328 customers for which it had decided not to submit the communication pursuant to art. 34 of the GDPR - had not correctly interpreted the provisions of Order No. 659 of November 2, 2024.
Specifically, with a note dated December 12, 2024 (ref. No. 146264), the Bank was asked to:
- provide complete feedback regarding the communications, including those to the 1,328 customers to whom the Bank had decided not to provide any communications;
- specify the methods of communication to the interested parties, via Online Reporting (ROL), App, and Internet Banking, also indicating the measures adopted to document the receipt and reading of the communication;
- specify whether, with reference to the sole proprietorships whose personal and banking data were subject to unauthorized access by the employee, communication was made pursuant to Art. 34 of the GDPR.
In a letter dated December 19, 2024 (ref. no. 149833), ISP provided feedback, noting:
- that it had sent the communication, pursuant to Article 34 of the GDPR, to the 1,328 customers previously excluded;
- that with respect to the previous point, excluding the 29 uncontactable customers and the 27 deceased, "communications were […] sent to 1,272 customers (NDG), broken down as follows: 476 customers (NDG) received the communication via Online Reporting (ROL), both via the app and via Internet Banking; the communication was visible to customers starting December 19th; 776 customers (NDG) received it via registered mail; on December 18th, the communications were delivered to the external supplier for printing and enveloping; as for the delivery of letters to Poste Italiane, this is expected to take place by December 19th in the majority of cases;
- "with regard to the methods for sending the communication, […] the criterion of preference expressed by the customer in the contractual context was followed, so those who opted for online reporting methods received the communications pursuant to art. 34 GDPR in digital form";
- "for customers enabled for the My Key remote banking service, a special notice (banner) has been made visible in bold, bold color (orange) and the wording "Important communication" and then "Notice of access to your personal data" on both the App and Internet Banking channels, indicating the presence of an important communication in the Archive section [...] This banner remains visible at every login and internal navigation until the customer clicks the "Read" button on the banner and, after the pop-up opens, also clicks the "I understand" button on the same pop-up. The pop-up can be closed by clicking the "X"; However, this closure is not equivalent to clicking the "I understand" button and therefore results in the banner being displayed again upon each subsequent access";
- "With regard to sole proprietorships whose personal and banking data were subject to unauthorized access, we confirm that, based on the checks carried out, the former employee accessed a total of 170 customers (NDG). Communications pursuant to Article 34 of the GDPR were sent to all these customers..."
On January 14, 2025 (ref. no. 4137), a further request for clarification was addressed to the Bank regarding the communications sent to interested parties via the App. The Bank responded to this request with a note dated January 24, 2025 (ref. no. 9754).
3. Initiation of the proceedings and integration of the investigation.
Taking into account the assessments carried out by the Authority's Digital Technologies and Cybersecurity Department, contained in a technical report prepared on March 3, 2025 (ref. no. 27544), the statements made by the parties, as well as the information acquired during the investigation, the Office, with a note dated May 27, 2025 (ref. no. 72300), following the investigations into the management of the data breach, notified the Bank, pursuant to art. 166, paragraph 5 of the Code, the initiation of proceedings to ascertain the alleged violations of Articles 5, paragraph 1, letter f), and paragraphs 2, 24, 32, 33, and 34 of the GDPR.
With a communication dated June 20, 2025 (ref. no. 88917), the Bank requested an extension of the deadline for submitting its defense briefs, which the Authority granted with a letter dated June 24, 2025 (ref. no. 89371).
On July 10, 2025 (file no. 98694), the Bank submitted its written submissions, arguing that:
- the inadequacy of the security measures adopted by the data controller cannot be inferred solely from the fact that a personal data breach has actually occurred, since the GDPR is intended to limit the risks of personal data breaches, not to eliminate them. The Court of Justice expressed this view in its ruling in Case C340/21, which stated that "Articles 24 and 32 of the GDPR must be interpreted as meaning that […] unauthorized access to such data by third parties pursuant to Article 4.10 of that regulation is not sufficient, in itself, to conclude that the technical and organizational measures implemented by the data controller were not adequate within the meaning of Articles 24 and 32." Therefore, the adequacy of the measures adopted by the data controller must be assessed on a case-by-case basis, "taking into account the risks associated with the processing in question and assessing whether the nature, content, and implementation of such measures are appropriate to those risks." Furthermore, in this specific case, given that the breach involved only access without data exfiltration by the employee, it appears to be "one of the most difficult to prevent," potentially confounding legitimate access operations due to the employee's duties.
- It cannot be demonstrated that the measures adopted were inadequate to prevent the data breach, to the extent possible. What is currently evident, however, is the lack of evidence of actual harm suffered by the data subjects and that the security measures adopted by the Bank "allowed the data breach to be intercepted."
- The security measures adopted by the Bank prior to the data breach already included measures such as employee training policies, an authorization system based on employee roles and duties, a logging system "designed to meet the requirements of Provision 192" adopted by the Authority in 2011, and an alerting and control system "created to identify potentially anomalous behavior related to consultations conducted by the Bank's operators."
- The Bank's alerting system had been strengthened and updated prior to the data breach and following measures already adopted by the Authority against the Bank (Provisions No. 270 of May 27, 2021, and No. 272 of July 28, 2022).
- The employee's conduct—difficult to predict, identify, and neutralize—emerged "precisely thanks to internal alerts," which, in line with Provision 192, were not immediately apparent. 192/2011 of the Authority, "allowed the activation of the additional levels of control and mitigation measures envisaged";
- the criteria used by the Bank to assess the severity of the data breach, particularly with regard to the execution of the so-called override (reclassification), contrary to what the Authority claims, were objective, given the lack of discretion in identifying these criteria, based on the ENISA methodology (also recommended by the EDPB "Notification Guidelines"); the absence of previous privacy alerts due to the employee's conduct; the cooperation and statements of the same employee; and the absence, to date, of evidence of the exfiltration of personal data as a result of the data breach;
- Regarding the alleged violation of the accountability principle, the latter does not require the data controller to conduct assessments that are "completely correct, nor does it require the controller to avoid breaches of the obligations set forth in privacy legislation," but rather to "comply with the general principles governing the processing of personal data and to be able to demonstrate such compliance." To argue otherwise, "any violation of personal data protection legislation by the data controller [...] would automatically also result in a violation of the accountability principle," with the associated consequences, including in terms of sanctions.
- The above is confirmed, in particular, by the interpretation of the accountability principle made by the Authority on the dedicated page of its website (https://www.gpdp.it/regolamentoue/attacco-basato-sul-rischio-e-misure-di-accountability-responsabilizzazione-di-titolari-e-responsabili), according to which data controllers are required to notify violations, as required by Article 13 of the GDPR. 33 of the GDPR, "only if they consider it likely that such a breach will result in a risk to the rights and freedoms of data subjects (see Recital 85)", in light of which "notification of the breach to the Authority is not mandatory"; from the Technical Report of the competent Department, which "traced the [override] case to Article 24 of the GDPR (and not Article 5, paragraph 2 of the GDPR)";
- with regard to the alleged violation of Article 33 of the GDPR, it would have acted in good faith, with regard to the indication contained in the notification of July 17, 2024, of nine individuals involved in the data breach, having considered only those to whom the greatest number of accesses had been made; This choice is also supported by the principles set forth by the EDPB in its "Notification Guidelines," which specify that "the GDPR allows for approximations regarding the number of natural persons affected [...] the focus should be on addressing the negative effects of the breach rather than providing exact figures."
- the accesses made by the employee did not present any abnormalities that would be considered incompatible with the performance of normal work duties;
- subsequent investigations "confirmed that the information transmitted by the Bank to the Data Protection Authority on July 17, 2024, and subsequently supplemented on August 30, 2024, was already sufficient to provide a sufficiently clear and complete picture of the incident [...] to allow the Authority to assess the extent of the data breach."
- regarding the alleged violation of Article 13 of the GDPR, 34 of the GDPR, even if such a breach were deemed to have occurred, it would be "lacking in harmfulness, having not proven to be [...] prejudicial" in the absence of data exfiltration.
With reference to the assessment criteria set forth in Article 83 of the GDPR, the Bank stated that:
- regarding the breach of the accountability principle, it:
• "cannot be considered serious, as it did not have any consequences for the data subjects;
• was of very limited duration, as the Bank promptly took action to further strengthen its safeguards."
- regarding the aspects pertaining to the data breach, it was "a harmless breach:
• as it did not have any consequences for the data subjects;
• as it was of limited duration, involving a single personal data breach."
- regarding the intentional or negligent nature of the breach, given that "Intesa's operations are consistently guided by the principles of good faith and transparency, in accordance with the applicable regulatory framework [...] even in the case of the data breach, the Bank's approach was guided by a concrete desire to comply with the provisions of the Regulation and the national implementing legislation," therefore the Bank "could be solely attributable to [...circumstances] based on minor negligence," also considering that the "Bank promptly adopted concrete and structured initiatives to strengthen its organizational data protection capabilities, specifically with the launch of the Nemo Program";
- In relation to the measures adopted by the controller to mitigate the damage suffered by data subjects, the Bank, through the Nemo Program, has established a working group to address various areas, including, but not limited to:
a) "the introduction of enhanced protection mechanisms for certain individuals holding positions of particular relevance for the constitutional order and/or national security (SEC customer register);
b) the strengthening of the internal system of ex ante authorizations and ex post controls, through both organizational and technical interventions;
c) the introduction of a dynamic data masking solution for masking customer data on summary systems and governance areas";
- In relation to any previous relevant violations committed, the Bank stated that it was the recipient of two relevant provisions on the matter, No. 270 of May 27, 2021, and No. 272 of July 28, 2022. In this regard, the Bank clarified that "the data breach in question was detected [...] precisely thanks to the alert system implemented by the Bank and strengthened over time, also as a result of the aforementioned measures."
- regarding the level of cooperation with the Supervisory Authority, the Bank stated that it provided full cooperation "not only by providing the information and clarifications requested, but also by implementing the measures prescribed by the Guarantor and adopting additional technical and organizational measures."
- regarding the categories of personal data affected by the breach, the Bank confirmed that the accesses concerned ordinary personal data.
- regarding the additional elements required by Article 83 of the GDPR for the purpose of quantifying any potential fines, the Bank stated in particular that the breaches in question did not "result in any economic or financial benefits for Intesa. Quite the opposite."
4. The applicable regulatory framework.
Article 5(1)(f) of the GDPR, in identifying the principles applicable to processing, establishes that personal data must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures ('integrity and confidentiality')."
Article 5(2) and Article 24 of the GDPR then define the principle of accountability, which places the data controller's overall responsibility for implementing appropriate technical and organizational measures to ensure, and to be able to demonstrate, that processing complies with data protection legislation.
It follows that data controllers are responsible for independently deciding on the methods, safeguards, and limits of personal data processing, in compliance with regulatory provisions and in light of certain specific criteria set out in the GDPR.
Article 32 of the GDPR, concerning the security of processing, also establishes that "taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk [...]" and that "when assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed" (Article 32, paragraphs 1 and 2 of the GDPR).
Article 33, paragraph 1 of the GDPR further provides that "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."
The "Notification Guidelines" highlight in this regard that "depending on the nature of the breach, the controller may need to conduct further investigations to establish all the relevant facts relating to the incident [...]. This means that the Regulation acknowledges that the controller does not always have all the necessary information about a breach within 72 hours of becoming aware of it, as full and comprehensive details of an incident are not always available within that timeframe. Therefore, the Regulation allows for phased notification. This is more likely to be the case with more complex breaches, such as certain types of cybersecurity incidents, where, for example, an in-depth forensic investigation may be necessary to fully establish the nature of the breach and the extent of the personal data compromise. Consequently, in many cases the controller will need to conduct further investigations and follow up on the notification by providing additional information at a later stage" (paragraphs 56 and 57).
This also allows the supervisory authority to assess the adequacy of the decisions taken by the controller regarding communication to data subjects and the measures taken to address the breach.
Article 34 of the GDPR establishes that "where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay," that "the communication to the data subject shall […] describe in clear and plain language the nature of the personal data breach and contain at least the information and the measures referred to in points (b), (c), and (d) of Article 33(3)" and that such communication is not required, in particular, if "the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the breach, in particular those designed to render the personal data unintelligible to any person who is not authorized to access it, such as encryption."
The GDPR also states that risk assessment should take into account both the likelihood and severity of risks to the rights and freedoms of data subjects and that such risks should be determined based on an objective assessment (see recommendations 75 and 76).
In this regard, the aforementioned "Notification Guidelines" identify the following factors to be considered—in the event of a personal data breach—in assessing the risk to the rights and freedoms of data subjects: the type of breach; the nature, sensitivity, and volume of personal data; the ease of identification of data subjects; the severity of the consequences for data subjects; the specific characteristics of the data subject; the specific characteristics of the data controller; and the number of data subjects affected.
The "Notification Guidelines" themselves emphasize that: "the Regulation states that communication of a breach to data subjects should occur 'without undue delay,' which means as soon as possible," given that the primary purpose of communication to data subjects is to provide them with specific information on the measures they can take to protect themselves; the data controller, among the measures to be taken to remedy the breach and mitigate its possible negative effects for data subjects, "should also provide specific advice to natural persons on how to protect themselves from the possible negative consequences of the breach."
5. The outcome of the investigation and the procedure for adopting corrective measures and sanctions.
The investigation revealed that a Bank employee accessed the financial information of 3,573 customers for over two years, "between February 21, 2022, and April 24, 2024," without any need for it in relation to his duties. He accessed the information 6,637 times, without the alert systems detecting any anomalies.
Among these customers, a number were found to be individuals holding a role of public importance. This circumstance further aggravates the gravity of the facts, considering that the Bank also manages treasury and cash services for members of parliament and high-ranking institutional officials designated by the Bank as politically exposed persons (PEPs).
For this reason, the employee was subjected to disciplinary proceedings and imposed a sanction pursuant to Article 7 of Law No. 300/1970.
5.1 Violation of Article 5, paragraph 1, letter f) and paragraph 2, of Article 24 of the GDPR. The principle of accountability and the security of processing
In relation to the proceedings in question, it is particularly significant that the Bank adopted the organizational decision to allow designated operators (such as the employee responsible for the improper consultations) to query, "in full circularity," not only the data of customers operating at their respective branches, but also the entire customer base, thus allowing access to all customer data.
This organizational decision, which is subject to the Authority's unquestionable review, inevitably entails the need to counterbalance this broad freedom of action of individual operators and to adopt adequate measures to reduce the risk that inappropriate behavior by an individual employee could negatively impact, as in this case, the rights and freedoms of data subjects. These measures, which the data controller has not been able to demonstrate, have been adopted.
Given the Bank's business model, which is geared toward full circularity, adequate precautions and controls are not implemented for access by customers outside of the Bank's portfolio or without active accounts. These include, for example, requiring prior authorization from a supervisor, or allowing limited access to customer data from other branches.
In a context that is certainly considered high-risk, given the bank's banking activities, the controls adopted by the Bank were therefore deemed insufficient to meet the obligations set forth in Articles 5, 24, and 32 of the GDPR. Additional measures, designed to prevent, detect, and promptly report suspicious access, would have been necessary, even if formally compatible with the authorization profiles issued to employees.
Given that the Bank uses digitalization as a key enabling factor for optimizing internal processes, security, and an increasingly inclusive and integrated offering of banking services, it would certainly have been able and required to implement appropriate contextual verification mechanisms regarding the actual operational need for its operators to access data, such as mandatory linking to pending contractual relationships, the introduction of dynamic authorization limitation systems, automatic consistency checks between role and accessed data, or alerts related to specific customer types.
Also considering the presence of politically exposed persons (PEPs) among the customers affected by the employee's unauthorized access, it is clear that the Bank's use of exclusively quantitative thresholds, with extended temporal frequencies, proved to be an unsuitable and ineffective measure to detect illegitimate conduct characterized by repeated but time-distributed access, which presumably remained below the alert thresholds established by the ISP.
In particular, with specific reference to the category of high-risk customers (i.e., publicly or politically exposed), it would have been necessary to implement enhanced controls.
In such cases, in application of the risk-based approach principle, the Bank should have implemented dedicated and more stringent controls, lower alert thresholds, and more frequent monitoring, considering that greater public visibility can naturally increase the risk of access for purposes unrelated to the management of ordinary operations.
Furthermore, it would have been necessary to provide automatic escalation mechanisms in the event of access outside of the context of ordinary operations, through immediate notification to the operator's direct supervisor and timely verification by the Bank's control functions (compliance, privacy, and security).
The failure to differentiate controls based on the status of a public or politically exposed person highlights the lack of an adequate risk assessment, as well as the adoption of belated and fragmented control measures, in violation of Articles 5, paragraph 1, letter f), and 32 of the GDPR.
In relation to the objections raised by the Bank in its defense briefs, regarding the Authority's criticism of the incorrect assessment of the severity of the event classified by ISP as "medium risk" due to the alleged presence of certain risk-reducing factors (such as, for example: the absence of previous privacy alerts, due to the employee's conduct, towards individuals other than the data subjects or towards the same data subjects; the employee's cooperation; the employee's statements regarding not having made copies or not having shared the accessed data with anyone), it is emphasized that attributing the cause of the incident to an employee's conduct does not in itself reduce the severity of the consequences for the data subjects, nor the likelihood of misuse of the accessed data, which the preliminary investigation did not rule out.
5.2 Violation of Article 33 of the GDPR. Notification of the "data breach".
Pursuant to Recital 75 of the GDPR, the risk must be assessed exclusively in relation to the rights and freedoms of natural persons, taking into account material and non-material damage, risks of fraud, identity theft, reputational damage, and discrimination.
From this perspective, the "Notification Guidelines" reiterate that the risk assessment must be conducted based on the severity and likelihood of impacts on the rights and freedoms of data subjects, without attributing decisive importance to the cause or origin of the breach.
The recommendations developed by the European Union Agency for Network and Information Security (ENISA), cited in the aforementioned "Notification Guidelines," require a structured risk assessment based on objective parameters geared towards the effects on data subjects, including the nature, sensitivity, and volume of the data, the number of data subjects involved, the characteristics of the data subjects (vulnerability, public exposure, role), and the severity and likelihood of impacts.
In this case, the override was applied by the Bank to reduce the risk based on the internal cause of the incident, without evidence of objective factors that effectively reduced the impact or likelihood of harm to the data subjects.
The presence of publicly and politically exposed persons among those affected by the improper questioning is also difficult to reclassify the risk through an override to reduce its scope.
In essence, the Bank declared in the proceedings that it applied the ENISA methodology but substantially deviated from it without objective and verifiable justification.
In light of the elements examined, therefore, the Bank's conduct constitutes a violation of the principle of accountability pursuant to Articles 5, paragraph 2, and 24 of the GDPR, as the risk assessment was not consistent, objective, and demonstrable, nor aligned with the declared methodology.
With regard to the content and timing of the data controller's notification to the Data Protection Authority as required by Article 13 of the GDPR, 33 of the GDPR, it is established that, although the Bank formally declared the notification issued on July 17, 2024, to be "complete," it was found to be largely incomplete regarding the actual scope of the data breach and the number of data subjects involved. It was only partially supplemented on August 30, 2024, significantly late, compared to the deadlines required by Article 33 of the GDPR.
The true extent of what happened emerged exclusively following the evidence of the facts, resulting from the publication of press reports and the investigation initiated by the Guarantor itself, which finally made the full scope of the event clear.
The data controller's explanation, according to which "the data breach was characterized by the Bank as a loss of confidentiality, potentially resulting solely in the personal data of some of the Bank's customers being accessed by unauthorized third parties, therefore appears to fail to take into account the seriousness of this conduct. Over time, this assessment is validated by the absence of any known consequences beyond the temporary compromise of data confidentiality. It is therefore confirmed that the information transmitted by the Bank to the Data Protection Authority on July 17, 2024, and subsequently supplemented on August 30, 2024, was already sufficient to provide a sufficiently clear and complete picture of the incident, in light of that context, to allow the Authority to assess the extent of the data breach and, if deemed appropriate, to request additional information."
The Bank's failure to provide a complete, exhaustive, and timely account of the true extent of the breach seriously compromised the Authority's ability to adequately assess the facts and promptly exercise its powers of intervention and support, precluding (or at least significantly delaying) the adoption of adequate measures to mitigate the risks to data subjects, in violation of Article 33 of the GDPR.
5.3 Violation of Article 34 of the GDPR. Notification to data subjects.
Regarding notification to data subjects pursuant to Article 34 of the GDPR, the Authority, in Order No. 659, adopted on November 2, 2024, disagreeing with the Bank's assessments in this regard, deemed that the personal data breach in question was likely to pose a high risk to the rights and freedoms of natural persons, given the nature of the personal data breach—which, under the conditions set forth in Article 13 of the Italian Criminal Code, 615-ter, may constitute a criminal offense; the categories of personal data affected by the breach; the severity and persistence of the consequences for natural persons that could arise from the breach (such as, for example, disclosure of information regarding financial status, reputational damage); and the controller's business sector, which requires a high degree of accountability on the part of its authorized personnel to maintain customer trust, particularly by satisfying their legitimate expectations of confidentiality and security of processing.
The considerations reported by the Bank in its defense briefs demonstrate an inadequate understanding of the controller's obligations towards data subjects, thus negatively impacting their rights, especially considering that some of them are also politically exposed persons or otherwise persons of public notoriety.
From this perspective, the disclosure required by Article 34 of the GDPR constitutes a necessary risk mitigation measure and preventive protection of data subjects' rights, regardless of evidence of (possibly) already occurring damage.
The delay in providing the aforementioned notification, which occurred only following the Authority's injunction, and its incompleteness effectively limited the data subjects' ability to take timely mitigation measures and exercise their rights in a fully informed manner, thereby increasing their exposure to risk and failing to comply with the provisions of Article 34 of the GDPR.
In this context, however, it is noted that, following the data breach, the Bank took steps to strengthen its safeguards through the aforementioned "Nemo Program."
It is believed, in fact, that the introduction of enhanced protection mechanisms for the data of certain individuals holding particularly high-level positions (so-called "SEC" clients) and the strengthening of the internal system of ex ante authorizations and ex post controls will allow for a strengthened (and more effective) control system aimed at addressing and preventing, to the extent possible, the risks of unauthorized access.
At the same time, strengthening governance processes is also essential, particularly with regard to data breach management, enabling a prompt escalation procedure for managing unjustified access to customer data, particularly for the most exposed parties.
6 Conclusions: Verification of violations and declaration of unlawfulness of processing. Corrective measures pursuant to Article 58, paragraph 2, of the GDPR.
For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office with the initiation of the proceeding pursuant to Article 166, paragraph 5 of the Code and are therefore unsuitable for dismissing this proceeding, given that none of the cases provided for in Article 11 of the Garante's Regulation No. 1/2019 apply.
The unlawfulness of the conduct carried out by Intesa Sanpaolo S.p.A., as set out above, has therefore been established in relation to Articles 5, paragraph 1, letter f), and paragraph 2; 24; 32; 33 and 34 of the GDPR.
With regard to the exercise of the corrective powers referred to in Article 58, paragraph 2, of the Regulation, we acknowledge that Intesa Sanpaolo S.p.A. has complied with the requirements set forth in Order No. 659, adopted by the Garante on November 2, 2024, and that, during the proceedings, it has also spontaneously adopted certain measures, reported in this decision (see paragraph 3 above), aimed at aligning, in accordance with the regulatory framework described above, the processing of customer data with the GDPR, which are shared by the Authority.
Furthermore, it is stated that the conditions set forth in Article 17 of the aforementioned Regulation No. 1/2019 of the Italian Data Protection Authority are met.
7. Adoption of the injunction order for the application of the administrative pecuniary sanction and additional sanctions (Articles 58, paragraph 2, letter i), and 83 of the GDPR; Article 166, paragraph 7, of the Code).
The Italian Data Protection Authority, pursuant to Article 58, paragraph 2, letter i) of the GDPR and Article 166 of the Code, has the power to impose an administrative pecuniary sanction pursuant to Article 83, paragraph 4, and paragraph 1, of the Italian Data Protection Authority. 5 of the GDPR, by issuing an injunction (Article 18 of Law No. 689 of 24 November 1981) in relation to the processing of personal data carried out by Intesa Sanpaolo S.p.A., which was found to be unlawful, as set out above.
The violation, found in accordance with the grounds set out in the reasoning, cannot be considered "minor," in light of the combined provisions of Recital 148 and Article 83 of the GDPR.
We believe it is appropriate to apply Article 83(3) of the GDPR, which provides that "if, in relation to the same or linked processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement." The total amount of the fine is calculated so as not to exceed the maximum fine set forth in the same Article 83(3). 5 of the GDPR.
With reference to the elements listed in Article 83, paragraph 2, of the GDPR, for the purposes of applying the administrative pecuniary sanction and its quantification, given that the sanction must "in any case be effective, proportionate, and dissuasive" (Article 83, paragraph 1, of the GDPR), it is noted that, in this case, the following circumstances were considered:
- the relevance of the nature of the violations, concerning the failure to comply with measures aimed at ensuring adequate security of personal data, the principle of accountability, and the proper management of obligations related to the data breach that occurred (Article 83, paragraph 2, letter a) of the GDPR); the large number of data subjects involved (approximately 3,500 customers); the duration of the violation (which lasted for over two years); and the consequences that the unlawful processing had on the legal status of the data subjects. In favor of the offender, however, the non-specific nature of the personal data being processed was taken into account (Article 83, paragraph 2, letter g) of the GDPR);
- with respect to the subjective element, the Bank's conduct was taken into account, whose procedural, organizational, and supervisory shortcomings allowed the offense to be materially committed by its employee (Article 83, paragraph 2, letter b) of the GDPR). Furthermore, for the purposes of assessing the sanction, the Bank's inadequate handling of the obligations required by Articles 33 and 34 of the Regulation regarding personal data breaches is also relevant. It emerged that the data breach notification occurred significantly later than the Bank became aware of it, and that, even after the complete notification was sent on August 30, 2024, the information provided to the Authority only provided a partial picture of the true extent of the breach;
- the adoption of measures aimed at mitigating the harm suffered by data subjects, which occurred belatedly and only in compliance with the provisions of Order No. 659, adopted by the Italian Data Protection Authority on November 2, 2024 (Article 83, paragraph 2, letter c) of the GDPR), resulting from an inadequate understanding of the data controller's obligations towards data subjects, thus negatively impacting their rights;
- the business decision to operate under a fully circular regime—which, by its nature, entails greater exposure to risks for customer data—without having previously adopted, in application of the principle of accountability, suitable measures to guarantee the security of such data, intervening instead only after the breach has occurred to contain its effects;
- there are previous relevant breaches committed by the Bank in its capacity as data controller and ascertained with the following orders: No. 270 of May 27, 2021 (web doc. no. 9718112); no. 272 of July 28, 2022 (web doc. no. 9812423); no. 202 of May 26, 2022 (web doc. no. 9784626) (Article 83, paragraph 2, letter e) of the GDPR); these precedents, although far less significant than the one addressed in this provision, should have prompted the Bank to review its internal procedures for securing data access by employees (which is possible, as evidenced by the measures adopted in paragraph 3), and its data breach management policies;
- Data controllers operating in the banking sector are required to fully implement the measures set forth in Provision no. 192 of 2011, in light of the current regulatory framework for the protection of personal data and technological developments. These factors would have required the Bank, in application of the principle of accountability, to progressively update and strengthen the measures adopted, also taking into account the concrete experience gained over time;
- the conduct of the Bank was taken into account, which, after the initiation of the proceedings, cooperated with the Authority (Article 83, paragraph 2, letter f) of the GDPR);
- the manner in which the Authority acquired full knowledge of the true extent of the violations, namely following press reports, given the lateness and incompleteness of the notifications sent by the Company (Article 83, paragraph 2, letter h) of the GDPR);
- With regard to any other aggravating or mitigating factors applicable to the circumstances of the specific case (Article 83, paragraph 2, letter k), the following mitigating factors were considered: the adoption of certain measures to align, in accordance with the regulatory framework described above, the processing of customer data with the GDPR, as set out in this decision (see above, paragraph 3), as well as the costs incurred by the Bank to implement these measures.
Furthermore, it is believed that, in this case, taking into account the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the GDPR), the financial situation of the offender, as reflected in the financial statements for 2024, is relevant.
In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative fine of €31,800,000.00 (thirty-one million eight hundred thousand euros) on Intesa Sanpaolo S.p.A.
NOW WITH ALL THE FOREGOING, THE GUARANTOR
declares, pursuant to Articles 57, paragraph 1, letter b) and c) of the GDPR, f) of the GDPR, the unlawfulness of the processing carried out by Intesa Sanpaolo S.p.A., with registered office at Piazza San Carlo 156, 10121 Turin, VAT No. 11991500015, pursuant to Art. 143 of the Code, for violation of Articles 5, paragraph 1, letter f), and paragraphs 2, 24, 32, 33, and 34 of the GDPR.
ORDERS
Intesa Sanpaolo S.p.A., pursuant to Art. 58, paragraph 2, letter i) of the GDPR, to pay the sum of €31,800,000.00 (thirty-one million eight hundred thousand/00 euros) as an administrative fine for the violations indicated in this order.
ORDERS
pursuant to Art. 58, paragraph 2, letter i) of the GDPR, to the same Bank, to pay the sum of €31,800,000.00 (thirty-one million eight hundred thousand/00 euros) as an administrative fine for the violations indicated in this order, according to the methods indicated in the attachment, within thirty days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981.
It is hereby stated that, pursuant to Article 166, paragraph 8 of the Code, the violator retains the right to settle the dispute by paying—again according to the methods indicated in the attachment—an amount equal to half of the fine imposed within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below;
ORDERING
- Pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Italian Data Protection Authority Regulation No. 1/2019, the publication of the injunction order on the Italian Data Protection Authority's website;
- Pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Italian Data Protection Authority Regulation No. 1/2019, the publication of this provision on the Italian Data Protection Authority's website;
- Pursuant to Article 17 of Regulation No. 1/2019, the recording of violations and measures adopted in accordance with Article 58, paragraph 2 of the Regulation in the Authority's internal register provided for by Article 57, paragraph 1, letter u) of the Regulation.
Pursuant to Article 78 of the GDPR, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150/2011, an appeal against this decision may be filed with the ordinary judicial authority, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days from the date of notification of the decision itself, or sixty days if the appellant resides abroad.
Rome, March 26, 2026
THE PRESIDENT
Stanzione
THE REPORTER
Stanzione
THE SECRETARY GENERAL
Montuori




