Garante per la protezione dei dati personali (Italy) - 280/2026
| Garante per la protezione dei dati personali - Case number: 280/2026
Internal number (from the DPA): 10252460 | |
|---|---|
| Authority: | Garante per la protezione dei dati personali (Italy) |
| Jurisdiction: | Italy |
| Relevant Law: | Article 5(1)(e) GDPR Article 5(1)(f) GDPR Article 32 GDPR Article 33 GDPR Article 34 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 08.04.2024 |
| Decided: | 17.04.2026 |
| Published: | |
| Fine: | 85,000 EUR |
| Parties: | Ambrosetti S.p.A. |
| National Case Number/Name: | Case number: 280/2026
Internal number (from the DPA): 10252460 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Italian |
| Original Source: | GPDP (in IT) |
| Initial Contributor: | ap |
The DPA fined a consulting company €85,000 for failing to ensure security of processing in relation to a data breach. In addition, the company did not inform the affected data subjects until ordered to do so by the DPA.
English Summary
Facts
Ambrosetti S.p.A. (the controller) is a consulting company. In 2024 the controller informed the DPA of a data breach, in accordance with Article 33 GDPR. The controller estimated that the data breach could have affected around 134,000 data subjects (later lowered to approximately 62,000), and concerned their contact details and login credentials. In addition, the controller stated that it was unlikely that the data breach posed a high risk for data subjects, since the credential data was the initial registration credentials set by the controller and not the user. Finally, the controller stated that it had hired external staff to develop a large number of their systems, and it had assumed that the system security was also monitored by the external staff.
During its investigations, the DPA found that some of the passwords in question appeared to be set by the data subjects and not the controller. The controller did not initially inform the affected data subjects, but later contacted data subjects it had an email address on file. The controller also published a notice on its website and contacted news outlets.
Holding
The DPA found a violation of Article 34 GDPR, as the controller failed to inform data subjects within the time limit, and had failed to justify the delay. The DPA considered that the data breach was likely to pose a high risk to the rights and freedoms of data subjects, and therefore, the controller had the obligation to inform them. The DPA took into consideration data subjects’ tendency to reuse passwords, the high number of affected data subjects, and the fact that the controller did not inform the data subjects until the DPA ordered it to do so during its investigations.
The DPA also found a violation of Article 5(1)(e) GDPR, as the controller had failed to comply with the principles of storage limitation. The DPA found that the controller retained authentication credentials when it was no longer needed (e.g. certain systems that were no longer in use). The DPA found that it was not necessary for the controller to store this data, especially considering the risks to data subjects’ rights and freedoms.
Finally, the DPA found a violation of Articles 5(1)(f) and 32 GDPR, as the controller failed to ensure security of processing. The DPA found that the controller stored a portion of the data subjects’ passwords in plain text. In addition, the DPA found that another portion of passwords (around 98,000) were not stored in a sufficiently robust manner.
The DPA fined the controller €85,000.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Italian original. Please refer to the Italian original for more details.
SEE ALSO Newsletter of May 21, 2026
[web doc. no. 10252460]
Measure of April 17, 2026
Register of Measures
No. 280 of April 17, 2026
THE ITALIAN DATA PROTECTION AUTHORITY
IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;
HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation");
HAVING SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter the "Code");
HAVING SEEN the preliminary notification of personal data breach submitted by The European House - Ambrosetti S.p.A. to the Authority on April 8, 2024, pursuant to Article 33 of the Regulation, and the subsequent supplementary notification submitted on May 23, 2024;
HAVING EXAMINED the documentation in the file;
HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Regulation of the Garante No. 1/2000;
REPORTER: Professor Ginevra Cerrina Feroni;
WHEREAS
1. The Office's investigation into the notified personal data breach, pursuant to Article 33 of the Regulation.
On April 8, 2024, The European House - Ambrosetti S.p.A. (hereinafter, the Company), pursuant to Article 33 of the Regulation, submitted to the Authority a preliminary notification of a personal data breach, resulting from "data exfiltration following unauthorized access by an attacker," affecting the personal and contact details (email address) and authentication credentials (username and password) of an unspecified number of data subjects.
The Company also stated that "technical investigations are still underway to identify the affected systems in detail" and stated that it had not communicated the personal data breach to the affected data subjects, believing that it was not likely to pose a high risk to the rights and freedoms of natural persons.
On April 9, 2024, the Office sent the Company an initial request for information to acquire useful information for assessing the personal data protection aspects. In a note dated April 17, 2024, the Company, while highlighting that it "intends to finalize [the notification] in all its aspects and consequent obligations once the technological investigation activities have been completed, presumably by May 30, 2024," stated, among other things, that:
"134,303 data subjects would be potentially involved. [...] The number is based on a preliminary estimate, but it is presumed to be lower, given that, given Ambrosetti's professional experience, individual data subjects often use different email addresses to authenticate to the services. The Company is carrying out all appropriate checks on this matter" (see note dated April 17, 2024, p. 2);
With the entry into force of the GDPR in 2016, the Company began a process of evaluating and implementing security measures to protect personal data in accordance with the new regulatory provisions. The following is a summary of what has been done to date and its impact on the matter under consideration. In 2018, Ambrosetti began implementing a password management system in web applications, deciding to adopt a password encryption system. Taking into account the state of the art, implementation costs, as well as the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Company therefore identified Bcrypt, one of the main consolidated tools on the market, as the algorithm to be used. Meanwhile, work continued to strengthen the protection systems, initiating the Company's parallel study and feasibility study of a new systemic and application architecture. Therefore, a selection and research activity was launched in 2021, culminating in the introduction of certified systems capable of Offer advanced security services for web applications to meet the needs of increased corporate security. The process being implemented by the Company, starting in January 2022, will only manage the authorization to register on Ambrosetti portals. […] The system automatically sends, to the user's email address provided by the client when establishing the contractual relationship with the Company for the provision of the agreed-upon services between the parties, a dedicated and personal link to the web page from which the user accesses the agreed-upon services, allowing the user to create and manage their own access credentials” (see note cited, p. 3);
"Regarding risk assessments for the rights and freedoms of data subjects, the Committee itself, in its "Guidelines 01/2021 on examples of notification of a personal data breach," clarifies that the proposed case analyses "explicitly refer to those under examination," with the aim of assisting data controllers in assessing data breaches affecting them. However, at the same time, "any change in the circumstances relating to the cases described [...] may result in different or more significant levels of risk, and therefore require different or additional measures," and notification can only be considered "good practice" in some cases. Therefore, assessments that take into account all the concrete elements existing in the specific case under consideration cannot be ignored" (see, cited note, p. 6);
“Ambrosetti, while analyzing the Guidelines and Case 06 referred to [… by] the Authority, in the risk assessment carried out, proceeded to examine in depth the specifics of the case in question, and came to the conclusion, taking into account what is known to date, that the risks to the rights and freedoms of the interested parties are negligible. In fact, from the investigations carried out to date by the Company, it appears that: 1. The exfiltrated data are all access credentials that are currently unusable, relating to systems no longer in use since 2022: starting from 2022, the method of storing access credentials to Ambrosetti systems has in fact changed […]. 2. The files referred to in the notified breach contain Ambrosetti customers' first registration credentials, set by the Company and released to customers after the definition of the contractual relationships governing the provision of training services to the staff agreed with them. It is the user's responsibility to proceed with changing the receipt password, in compliance with the security constraints imposed on the system. Upon expiration of the contract concluded with the Company's client, the students' accounts are automatically deactivated, and this makes it impossible to access Ambrosetti services using said credentials. 3. It also emerged that 96% of the exfiltrated data relates to accounts inactive since 12/31/2023 and, therefore, unusable. With regard to the remaining 4%, following the discovery of the breach in question, the Company promptly imposed the obligation for the user to change their password. Given that this data is therefore obsolete in at least 96% of cases and in any case the credentials are unusable as they relate to systems no longer in use, and since these are first-time registration credentials not set by the user, there are no risks associated with the habit of users using the same or similar password to access other online services. 4. Furthermore […] it also emerged that only "in one case, the passwords were stored in clear text". This is the file called "sgc_login.csv", which appears to be an extraction from a database relating to an application no longer in use since November 18, 2020, and therefore such data is technically not usable to access the Company's services. 5. It should also be noted that the breach essentially does not concern data processed in a business-to-consumer relationship, but rather business-to-business; therefore, the data subjects, pursuant to the law, have received policies from their employers indicating specific precautions for managing passwords used in the performance of their duties, as well as adequate training in this regard. 6. The breach in question concerns initial registration credentials for the Company's websites through which it provides professional training services, and therefore the nature of the sites and the hypothetically accessible data do not generate negative connotations for the data subjects. In fact, no special categories of data are present, such as judicial data or payment data, data revealing membership of a trade union, or data revealing health status” (see note cited, pp. 6, 7);
"Following the discovery of the event, the Company promptly cancelled all passwords for accessing the Ambrosetti systems referred to in the exfiltrated files, requiring active users to update their passwords, in compliance with the security constraints imposed by the Company for accessing its systems" (see note cited, p. 7);
"The Company immediately organized a multidisciplinary team dedicated to the matter, composed of internal ICT representatives, the DPO, and external cybersecurity consultants, which continues to manage and monitor the ongoing investigations" (see note cited, p. 7).
On April 18, 2024, the Office sent the Company a second request for information to acquire further information regarding the personal data breach. It highlighted that, following a technical assessment of the data disseminated online, some of the passwords in question appeared to have been set by the users to whom they referred.
With a note dated April 24, 2024, the Company responded to the aforementioned request for information, stating that:
The authentication credentials disclosed related to the Company's various online services or web applications ("aggiornamentoconoscenza.it", "cocircle.ambrosetti.eu", "fondir.ambrosetti.eu", "healthcare.ambrosetti.eu", "innotechhub.ambrosetti.eu", "live.ambrosetti.eu", "management.ambrosetti.eu", "www.aggiornamentopermanente.it", "www.ambrosetti.eu", "www.ambrosettilive.eu", and "www.leaderdelfuturo.it") (see note dated April 24, 2024, pp. 1-3);
"The aforementioned applications allow potential access only to users who had activated the service provided through the application, making authentication technically impossible for customers who had not purchased the relevant service. All the portals […] referenced only allowed access to training content such as slides, research, and presentations, or registration for events organized by the Company" (see note cited, p. 3);
"The user categories to which the authentication credentials refer are: employees of the Company's customers and employees of the Company. In the AP_USERS-AMBROSETTI.CSV file, the email address contained was not a real one, and therefore, neither directly nor indirectly, allowed the identification of a natural person; rather, it was simply entered as a mandatory field because it was technically required by the application" (see note cited, p. 3);
"The cryptographic functions adopted for each individual file are specified:"
login_users.csv: "MD5 (Message Digest Algorithm 5), a widely used cryptographic hash function supported by a wide variety of software and hardware for calculating the hash of a string or message. It is known for its computational efficiency, simplicity, widespread use, and compatibility, making it a solution compatible with the variety of software and hardware used by the Company at the time."
ldf_users.csv: "The site is developed with Joomla 1.5 and uses MD5 with a 32-character salt added to the end of the password string."
ap_users.csv: "The site is developed with Joomla 1.5 and uses MD5 to hash passwords. When passwords are created, they are hashed with a 32-character salt added to the end of the password string."
chat_users.csv and uni_login.csv: "mixture of MD5 and MD5 with a 32-character salt added to the end of the password string" (see cited note, p. 4);
regarding how the passwords in question were set:
login_users.csv: "The passwords were set by a system administrator when the user was created and can then be changed by the user. Because MD5 encryption is used, it is not technically possible to verify whether the passwords were preset by the administrator or changed by the user."
sgc_login.csv: "The passwords were set by a system administrator when the user was created and can then be changed by the user."
ldf_users.csv and ap_users.csv: "The passwords were set by a system administrator when the user account was created and can then be changed by the user. Since the MD5 cryptographic function with salt is present, it is not technically possible to verify whether the passwords were preset by the administrator or changed by the user."
chat_users.csv and uni_login.csv: "The passwords were set by a system administrator when the user account was created." (see cited note, pp. 4, 5);
One of the Company's web applications ("aggiornamentoconoscenza.it") was discontinued in March 2020, while the other web applications underwent password hashing algorithm updates between February 2020 and October 2022 (see cited note, p. 5);
The Company retains personal data processed in the performance of the activities agreed with customers for ten years following the termination of the relationship with the customer, in order to fulfill regulatory obligations (e.g., tax, accounting) that remain in place even after the termination of the relationship, as well as to enforce the rights arising from the contract in court. To this end, it is noted that the Company, given the type and variety of services provided and the long-standing relationships with its customers, has adopted a commercial practice for managing contractual relationships with customers that tends to favor the definition of framework agreements, which generally govern the relationship between the parties and have an indefinite duration, without prejudice to the right of each party to terminate the relationship with adequate notice, alongside individual offers governing the specific activities requested from time to time. Furthermore, the services provided by the Company are also characterized, by their very nature, by the repetitive nature of requests for similar types of services from the same customer over time (e.g., training services repeated at agreed intervals, but relating to different topics and therefore governed by specific offers), resulting in the continuation of relationships with its customers over time, which therefore requires the retention of their data” (see note cited, p. 6);
“When requesting a new password, the user received the following message: […] It is not recommended to use a password already used in other systems. The password must be at least 8 characters long and include at least one special symbol, one uppercase letter, one lowercase letter, and one number. […] Pending the completion of the ongoing investigations, no further communications have been sent to users to date” (see note cited, pp. 6, 7);
“Only a limited number of customers have requested further information on this well-known matter. In these cases, ad hoc meetings have therefore been held with the respective IT technicians and DPOs, who, to date, have all agreed that the risk has been overlooked” (see note cited, p. 7).
Subsequently, with the supplementary notification dated May 23, 2024, the Company provided further information on the measures taken following the personal data breach and confirmed its nature and scope.
On that occasion, the Company also reiterated that it had not communicated any information to the data subjects pursuant to Article 34 of the Regulation.
Pending the investigation, the Office then assessed the compliance of the measures undertaken by the Company following the breach, with particular reference to compliance with the notification obligations pursuant to Article 34 of the Regulation towards the data subjects to whom the breached authentication credentials refer.
In particular, from examining the information provided, the Garante deemed that the personal data breach in question was likely to pose a high risk to the rights and freedoms of natural persons, contrary to the Company's claims. Therefore, with Order No. 327 of May 23, 2024 (web doc. no. 10037682 at www.garanteprivacy.it), ordered the Company, pursuant to Articles 34, paragraph 4, and 58, paragraph 2, letter e), of the Regulation, to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques.
With the aforementioned order, the Authority also requested the Company to provide adequately documented feedback regarding the steps taken to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques.
In compliance with this, in a note dated June 7, 2024, the Company stated that:
"The communication was made directly to the interested parties for whom the company has an email address. On June 7, 2024, the Company therefore sent the text contained in document Annex 1 – 240607 Communication to Interested Parties to 54,917 interested parties" (see note dated June 7, 2024, p. 1);
In order to ensure similar effectiveness even for data subjects with whom there is no direct contact, the Company has opted for different communication channels, providing:
on 07/06/2024, a dedicated page was published on its company portal, available at this link: https://www.ambrosetti.eu/news/violazione-informatica-in-the-european-house-ambrosetti/
on 07/06/2024, the text of the document (Annex 2 – 240607, Press Release Website) was sent to 25 newspapers, listed in Annex 3 – 240607, List of newspapers sending CS, databreach_070624, for publication on widely distributed channels. (see note cited, p. 1).
On June 12, 2024, the Office sent the Company a third request for information, seeking further information regarding the Company's compliance with the aforementioned order from the Data Protection Authority.
With a note dated June 17, 2024, the Company responded to the aforementioned request for information, stating that:
"The number of data subjects with whom the Company does not have direct contact is 12,709. Due to the necessary manual cleanup and the identification of certain users, this number may be further reduced" (see note dated June 17, 2024, p. 1);
On June 17, 2024, ANSA published the press release sent by the Company in the "paywall" area; "Following the press releases sent to other newspapers, the Company has been actively requesting the publication of the press release since last week. Discussions are currently underway with Corriere della Sera, Il Sole 24 Ore, and Repubblica to agree on a possible further publication" (see note cited, pp. 1, 2);
"In the absence of a direct link between the affected residues not reached by email and their respective companies, we have launched a campaign on TEHA's social media channels" (LinkedIn, Facebook, X, Threads, and Instagram) (see note cited, p. 3);
"The Company has sent a press release containing an incident report to the requesting companies, requesting that they disseminate the incident widely within the Company (e.g., by posting it on the intranet and/or company noticeboard) in order to maximize its awareness among their employees" (see note cited, p. 3).
Subsequently, in a note dated July 3, 2024, the Company provided further updates regarding the additional measures taken to inform the affected parties, stating, among other things, that:
"Ambrosetti sent a detailed statement to 83 of its client companies, employing 11,264 affected parties [...], also requesting that company to widely disseminate the incident internally (e.g., by posting it on the intranet and/or company noticeboard) to maximize its reach among the affected parties. Following the above communication, four companies requested further clarifications, which were provided during videoconference meetings" (see note dated July 3, 2024, p. 1);
"The press release regarding the personal data breach was published in the national newspaper "La Repubblica" on July 1, 2024, on page 14 [...], with a print run of 125,502 and a circulation of 138,093 copies" (see note cited, p. 2);
"On the homepage of the company website, accessible at www.ambrosetti.eu, positioned at the top center and highlighted by an orange frame [...], a specific notice regarding the breach continues to be published, containing a link to the web page where Ambrosetti's news and communications on the matter are available" (see note cited, p. 2);
"TEHA's social media campaign continues" (see note cited, p. 2);
"For the sake of completeness, we hereby announce […] the recent development in the group's corporate reorganization. On July 2, 2020, TEHA Group S.p.A. was established, a company subject to the management and coordination of The European House - Ambrosetti S.p.A., which will be responsible for operational activities" (see note cited, p. 3).
Following its technical assessments, the Office prepared a specific technical report on July 22, 2024, which identified a violation of the obligations under Article 34 of the Regulation in relation to the Company's late notification of the personal data breach to users of its online services whose passwords were stored in clear text or using non-state-of-the-art encryption techniques. Furthermore, the Office identified a violation of the principles of storage limitation and integrity and confidentiality pursuant to Article 5, paragraph 1, letter b) of the GDPR. 166, paragraph 5, of the Code, notifying the Company of the alleged violations of the Regulation, with reference to Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation, for having stored user passwords, either in clear text or using sub-state-of-the-art cryptographic techniques, for having retained the authentication credentials of the same users for certain systems no longer in use, and for having failed to inform the data subjects affected by the personal data breach, as required by law.
In defense briefs dated October 16, 2024, the Company argued that:
- "The breach involved the name, surname, username (corresponding to the email address), and password for accessing Ambrosetti services. The processing of these categories of data is necessary for the performance of the services offered by the Company to its clients (e.g., training, consulting, etc.)" (see note dated October 16, 2024, p. 1);
- "The Company initially did not consider the breach likely to pose a high risk to the data subjects, having in any case, immediately upon discovery, required the change of access credentials to its services, and also initiated an in-depth analysis of the event" (see note cited above, p. 1);
- "Based on the information available at the time, 134,303 data subjects were potentially involved. The analyses conducted by Ambrosetti to date have allowed us to limit the number of data subjects involved to 61,670. By applying a progressive de-duplication process, considering rows referring to the same name/surname and email address as equal, duplicates were eliminated (e.g., users present multiple times, with the same name and surname followed each time by different numbers; users entered multiple times with "Name/dot/Surname", "Name/space/Surname", "NameSurname", "NameSurnameNumber"; email addresses present multiple times, preceded or followed by special characters). This automatic normalization of the fields was followed by a further manual update aimed at eliminating users that could not be traced, either directly or indirectly, to natural persons, such as fictitious users, thus reducing the number of data subjects in this case. The in-depth analyses carried out by the Company in recent months have also allowed us to to specify that 25,705 data subjects whose accounts were archived with unencrypted passwords were involved" (see note cited, pp. 1, 2);
- "following the aforementioned technical analyses, as well as based on the communications exchanged with [… the] Authority, the Company communicated the breach using the methods already detailed. Specifically, the breach notification was sent via email to 54,917 individuals, equal to 89% of the total data subjects in this case. Ambrosetti also informed the data subjects by contacting their client companies where the data subjects work, by publishing a specific banner on the homepage of its website, through dedicated posts on the company's social media channels, and by publishing the press release […] on Ansa.it and in the national newspaper "La Repubblica"" (see note cited, p. 2);
- "The conduct was not intentional because the company was neither conscious nor willing to violate specific laws nor to cause or accept, even potentially, risks to the interested parties" (see note cited, p. 2);
- "The services provided by the Company, by their very nature, are characterized by the repetitive nature of similar requests from its customers for similar types of services from the same customer (e.g., training services repeated at agreed-upon intervals). In response to customer needs for the launch of agreed-upon projects, the Company therefore tends to favor the establishment of agreements initially governing the ongoing relationships between the parties, generally of indefinite duration, alongside individual orders/quotes detailing the activities requested from time to time. As long as the relationships with its customers continue, the processing of their personal data (such as name, surname, email) is therefore necessary for the Company to provide its services" (see note cited, pp. 2, 3);
- "The Company has long been committed to continuously improving the security of its applications and data, including access protection and management, with a view to continually strengthening systemic and application resilience" (see note cited, p. 3);
- "Immediately after the incident was discovered, the obligation to change the access credentials to the Ambrosetti systems contained in the exfiltrated files was imposed, requiring the company to update its passwords, in compliance with the security constraints imposed by the Company for access to its systems. The Company immediately organized a multidisciplinary team dedicated to the matter, composed of internal ICT representatives, the DPO, and external cybersecurity consultants, which continues to manage and monitor the matter to this day. The Company has communicated the incident" (see note cited, p. 3);
- "Since 2016, the Company has begun a process of evaluating and implementing security measures to protect personal data in compliance with the new regulations on personal data, initiating, to this end, the study and feasibility of a new corporate system and application architecture. A selection and research process has therefore begun, culminating in the introduction of certified systems capable of offering advanced security services for web applications to meet the need to increase corporate security. The process being carried out by the Company, starting in January 2022, will only allow users to register on Ambrosetti portals, allowing them to create and manage their own access credentials based on the rules and Access Control Lists (ACLs) defined in the system. [OMISSIS] (see note cited, pp. 3, 4);
- "[OMISSIS]" (see note cited, p. 4);
- "The breach exclusively concerned the identification and access data of the data subjects and did not affect special categories of data." personal” (see note cited, p. 4);
- “the Company became aware of the potential violation from a post published on the social network “X” and, having verified the validity of the information, notified the violation to the Authority” (see note cited, p. 4);
- “during the COVID-19 pandemic, the Company was forced to rapidly modify the methods of providing its services, drastically increasing remote activities, which, from residual, became, given the very nature of Ambrosetti's business, the only possible ones. This led to a consequent exponential increase in requests for the activation of new tools and methods, to be made operational within a much shorter timeframe than the ordinary implementation process the Company had in place, and with reduced staff resources, given the health emergency […]. This emergency situation therefore contributed to the materialization and failure to promptly detect the oversight of 2020, which led to the failure to comply with company procedures, adopted since 2018, which provided (and provide) for the adoption of adequate security measures and the deletion of personal data whose processing is no longer necessary, such as that relating to applications no longer in use, as well as periodic checks on what has been implemented" (see note cited, p. 5).
On December 16, 2024, the Company held a hearing, as requested by the Company. At that time, the party stated that:
- "Regarding the violation of Article 34 of the Regulation, the Company initially decided not to send the notification of the violation to the interested parties, as it was particularly concerned about the potential reputational risks arising from sending such a notification, which would have had a media impact at a time when the Company was busy, on the one hand, organizing the fiftieth edition of the Cernobbio forum, which was held in early September 2024 […] and, on the other, managing a series of changes to its corporate structure (liquidation of one of the residual shareholders from the Ambrosetti family; establishment of TEHA Group S.p.A.; transformation of contracts signed with its employees into permanent contracts)";
- "The Company terminated its relationship with the previous DPO [...], as it believed it had not received adequate training and information from him regarding the rights and obligations established by the Regulation towards the Data Controller, as well as in assessing the risks arising from the personal data breach."
- "The personal data breach occurred through unauthorized access to a database serving approximately ten applications. A SQL injection vulnerability was exploited, which was discovered only post-incident."
- "The development of the aforementioned applications had been entrusted to external personnel initially employed to perform tasks related to the IT system component. With the growing need to rapidly develop a considerable number of applications, due to the ever-increasing importance of online presence following the restrictions imposed to combat COVID-19, these suppliers have also found themselves increasingly involved in the application sphere. The applications managed by the Company have thus grown exponentially during the pandemic, and greater emphasis has been placed on their operational management rather than systematic monitoring of their application security, assuming that security was being performed by the aforementioned suppliers."
- "Following the breach, the Company realized that the external suppliers did not have the adequate skills to develop these applications, also taking into account security and personal data protection aspects."
- "At the time of the personal data breach, improvements had been made to the IT authentication procedures used within the aforementioned applications through the adoption and integration of new IAM (identity access management) systems and the introduction of a second authentication factor";
- "The Company was unaware that user passwords were still stored within the aforementioned database, nor of the technical measures adopted by external providers to protect them";
- "Following the personal data breach, the Company implemented a series of initiatives and investments to adopt additional technical and organizational measures [...], including: the decision to initiate a process to obtain ISO 27001 certification; the termination of contracts with external vendors lacking security expertise for the application development component and after remediation of the identified vulnerabilities; the definition of a procedure for assigning tasks to external ICT vendors that also included an assessment of their cybersecurity skills; the early termination of the contract with the previous DPO [...] and the signing of a different contractual relationship with a new DPO; the provision of training initiatives for staff; and the strengthening of the IT department with the active search for a new manager. [...] The Company has initiated a process of accountability and change regarding personal data protection, which will allow it to better manage any future breaches."
3. The outcome of the investigation and the procedure for adopting corrective and disciplinary measures.
Following an examination of the statements made to the Authority during the proceedings and the documentation acquired, it appears that the Company, as data controller, performed certain processing operations that did not comply with the regulations on personal data protection for the reasons set out below.
In particular, it was established that the Company failed to notify the data subjects of the personal data breach pursuant to Article 34 of the Regulation, despite the breach being likely to pose a high risk to the rights and freedoms of natural persons.
Furthermore, the Company retained user passwords, either unencrypted or using sub-state-of-the-art encryption techniques, and retained the authentication credentials of the same users affected by the breach for certain systems no longer in use.
In this regard, it is noted that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Garante, falsely declares or certifies information or circumstances, or produces false documents or records, is liable pursuant to Article 34 of the Regulation. 168 of the Code "False declarations to the Guarantor and interruption of the performance of the duties or exercise of the powers of the Guarantor."
3.1. The applicable regulatory framework.
Article Article 34 of the Regulation provides that "where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay" (paragraph 1), that "the communication to the data subject shall […] describe in clear and plain language the nature of the personal data breach and contain at least the information and the measures referred to in points (b), (c) and (d) of Article 33(3)" (paragraph 2), and that such communication is not required, in particular, if "the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those designed to render the personal data unintelligible to any person who is not authorized to access it, such as encryption" (paragraph 3, letter a).
Article 5, paragraph 1, of the Regulation provides: Article 1(1) of the Regulation establishes that personal data must be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed [...] ('storage limitation')" (letter e)) and must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures ('integrity and confidentiality')" (letter f)).
Article 1(1) of the Regulation Article 32 of the Regulation, concerning the security of processing, further provides that "taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk" (paragraph 1) and that "when assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed" (paragraph 2).
With specific reference to the measures to be implemented when retaining user passwords, the Italian Data Protection Authority (Garante), in collaboration with the National Cybersecurity Agency (AGI), has adopted specific guidelines on password retention (Provision No. 594 of December 7, 2023, web doc. No. 9962283 at www.garanteprivacy.it). These guidelines provide data controllers and processors with guidance and recommendations on state-of-the-art password hashing algorithms, noting, among other things, that: "It is essential that password hashing algorithms meet the following requirements:
a computational complexity such that it is quick to calculate a single digest, but excessively expensive to calculate a large number of them, thus discouraging attackers from attempting to find user passwords;
a memory capacity required such that RAM is saturated when many digests are calculated simultaneously.
For these reasons, when it comes to password hashing, ad hoc algorithms are needed that aim to slow down the attacker's offensive capabilities.” (p. 7).
It was also recalled that “it is strongly discouraged to calculate a digest for password storage through the simple single application of a cryptographic hash function such as those indicated [… in the “Cryptographic Function Guidelines – Hash Functions” adopted by the ACN]” (p. 9).
3.2. Failure to notify data subjects of the personal data breach.
It was first ascertained, based on the findings of the specific technical report drafted on July 22, 2024, that the Company failed to inform the data subjects affected by the personal data breach, amounting to 61,670.
This was because the Company deemed that the personal data breach, affecting the authentication credentials (username and password) of users of its online services, was not likely to pose a high risk to the rights and freedoms of natural persons.
Contrary to the Company's claims, the Italian Data Protection Authority, in its Order No. 327 of May 23, 2024, held that the personal data breach was likely to pose a high risk to the rights and freedoms of natural persons and that the Company should therefore notify the data subjects pursuant to Article 34, paragraph 1, of the Regulation.
This was based on a variety of factors, in particular: the nature of the personal data breach, which occurred as part of a cyber attack aimed at acquiring authentication credentials (username and password, in some cases in the form of a text string, also known as a digest) and other personal data (including name, surname, and email address, in some cases fictitious); The severity and persistence of the potential consequences for natural persons that could arise from the use of the disclosed authentication credentials to unlawfully access computer systems or online services and consult, or acquire, personal data of the data subjects to whom they refer or of other categories of data subjects.
In this regard, it is also necessary to take into account the methods used to set passwords (which, in the absence of evidence to the contrary, should be considered, as a precaution, as if they had been chosen by each user) and the habit of users using the same password, even over time, for the same or other computer systems or online services, or, in any case, using similar passwords with only a few characters changed.
The large number of data subjects to whom the authentication credentials in question refer and the ease with which it is possible to trace specific natural persons, identified or identifiable, from the personal data affected by the breach were also taken into consideration; The low level of security guaranteed by the cryptographic functions used to protect user passwords stored on the Company's systems, in terms of resistance to the most common cyber attacks (e.g., brute force or dictionary attacks) aimed at identifying the password that generated a given digest.
In particular, with regard to this last factor—which must also be assessed in light of the indications and recommendations provided by the Authority in the aforementioned password retention guidelines, prepared in collaboration with the National Cybersecurity Agency—it emerged that some passwords (approximately 98,000) were retained after applying a hashing function (MD5, not always using a salt) that was unable to ensure an adequate level of security, while others (approximately 36,000) were even retained in clear text.
Therefore, with the aforementioned provision of May 23, 2024, the Authority—also taking into account the fact that none of the conditions set forth in Article 34, paragraph 1, of the Italian Legislative Decree were met. 3 of the Regulation, in the presence of which notification to data subjects following a data breach is not required, ordered the Company to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques. The Company must describe the nature and potential consequences of the breach in clear and simple language, as well as provide specific guidance on the measures that data subjects can take to protect themselves from any negative consequences of the breach.
Only following the corrective measure adopted by the Authority did the Company inform the data subjects involved in the personal data breach, pursuant to Article 34 of the Regulation, by sending a communication to 54,917 data subjects for whom it had an email address and by making public communications to inform the remaining 12,709 data subjects.
These public communications were made through press releases published on the Company's website and social media channels, and in a national newspaper. They were also sent to several client companies (where numerous interested parties work), with the request to disseminate them widely within their organizations to maximize their awareness among the interested parties involved.
In particular, it emerged that the personal data breach was communicated to the affected data subjects late, compared to the time the Company became aware of it (April 4, 2024). Approximately 55,000 data subjects were informed only on June 7, 2024, through a direct communication, while approximately 13,000 data subjects were informed only through public communications made in June and July 2024.
In this regard, the Company specified that the reason for the delay in communication was that "the Company initially did not consider the breach likely to pose a high risk to the data subjects" (see note 16/10/2024, p. 1) as well as "because of particular concern about the potential reputational risks arising from sending such a communication, which would have had a media impact at a time when the Company was busy organizing the fiftieth edition of the Cernobbio forum, which was held in early September 2024 […] and, on the other hand, to manage a series of changes relating to the corporate structure (liquidation of one of the residual shareholders of the Ambrosetti family; establishment of TEHA Group S.p.A.; transformation of contracts signed with its collaborators into permanent employment contracts)” (see minutes of the hearing of 12/16/2024).
The reasons given by the Company do not justify the delay in submitting the notification pursuant to Article 34 of the Regulation, which was also the result of a corrective measure by the Authority.
Furthermore, it is noted that allowing reputational reasons to prevail over the data subjects' data protection rights represents a clear failure to comply with the principle of accountability, to which the data controller is obliged to conform the processing it performs.
By late notification of the personal data breach, the Company therefore violated the provisions of Article 34 of the Regulation.
3.3. Data security.
During the investigation, it also emerged that, at the time of the personal data breach, some passwords (approximately 98,000) were stored using a hashing function (MD5, not always using a salt), while others (approximately 36,000) were even stored in clear text.
The aforementioned hashing function used, however, is not cryptographically robust, and its use is therefore not an effective measure to protect user passwords. Serious vulnerabilities in this function have been known for several years, allowing the password that generated it to be traced back to a digest.
In this regard, it should be noted that storing passwords using state-of-the-art cryptographic techniques is one of the measures that must be adopted to adequately protect the passwords of users of a computer system or online service.
Storing user passwords in clear text, or using non-state-of-the-art cryptographic techniques, therefore violates Article 5, paragraph 1, letter f), and Article 32 of the Regulation, which, in paragraph 1, letter a), expressly identifies encryption as one of the possible security measures suitable for ensuring a level of security appropriate to the risk (see also Article 83 of the Regulation, which states that "the controller [...] should assess the risks inherent in the processing and implement measures to limit those risks, such as encryption"). The Authority has recently issued a statement to this effect (see Decision No. 759 of 13 November 2024, web doc. No. 10109352 at www.garanteprivacy.it; Decision No. 198 of 11 April 2024, web doc. No. 10013321).
During the investigation, it also emerged that the authentication credentials (and other personal data) involved in the breach "relate to systems no longer in use since 2022." Specifically, the web application "aggiornamentoconoscenza.it" was discontinued in March 2020, while the other web applications to which the aforementioned authentication credentials allowed access underwent password hashing algorithm updates, carried out between February 2020 and October 2022.
In this regard, it should be noted that the retention of authentication credentials (username and password)—taking into account the high risks to the rights and freedoms of natural persons posed by such processing—should be carried out only for the time strictly necessary to achieve the purposes for which such data is processed, such as, for example, verifying the identity of users for access to IT systems or online services or, where applicable, ensuring their security (e.g., storing the most recent passwords set to prevent reuse by the user, so-called password history, or backups to ensure the restoration of the IT authentication system in the event of an incident).
This is also due to the fact that technological progress, over time, may compromise the effectiveness of the technical measures adopted to protect user passwords.
With reference to the Company's statement during the hearing regarding the fact that the application security of the systems was the responsibility of external suppliers and that the Company itself, following the breach, "realized that the external suppliers did not have the adequate skills to develop such applications, also taking into account aspects relating to the security and protection of personal data" (see hearing minutes of 12/16/2026), it is recalled that the Company acted as data controller with respect to the processing operations covered by these proceedings and that, in light of this, and specifically pursuant to Article 4, point 7, of the Regulation, it should have fulfilled the obligations incumbent on the data controller, including the application of the principles of storage limitation and integrity and confidentiality pursuant to Article 5, paragraph 1, letter b). e) and f) of the Regulation, as well as the adoption of the security measures referred to in art. 32 of the Regulation.
Furthermore, it is specified that, where the data controller decides to carry out processing through data processors, it must use only processors providing sufficient guarantees to implement appropriate technical and organizational measures so that the processing meets the requirements of the Regulation and guarantees the protection of the data subject's rights.
It is therefore clear that, in this case, even considering the Company's declarations in this regard, the company itself is at fault (see Article 28 of the Regulation).
The Company has therefore violated Article 5, paragraph 1, letters e) and f), of the Regulation, as well as Article 32 of the Regulation.
4. Conclusions: Declaration of unlawfulness of the processing. Corrective measures pursuant to Article 58, paragraph 2, of the Regulation.
For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office in the initiation of the proceedings. Therefore, they are unsuitable for dismissing this proceeding, given that none of the cases provided for in Article 11 of the Garante Regulation No. 1/2019 apply.
The Company's conduct, and specifically the failure to notify the data subjects affected by the personal data breach pursuant to Article 34 of the Regulation, as well as the violation of the obligation to adopt adequate technical and organizational measures to ensure a level of security appropriate to the risk, are unlawful, as set out above, in relation to Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation.
The breach established in the terms set out in the grounds cannot be considered "minor," given the nature of the multiple breaches established, which concerned the general principles of processing as well as the obligation to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and the obligation to communicate, without undue delay, a personal data breach to data subjects when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
Therefore, given the corrective powers granted by Article 58, paragraph 2 of the Regulation, an administrative fine is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, paragraph 2, letter i) of the Regulation).
5. Adoption of the injunction order for the application of the administrative fine and additional penalties (Articles 58, paragraph 2, letter i) and 83 of the Regulation; Article 83 of the Regulation; 166, paragraph 7, of the Code).
As a result of the proceedings, it is therefore found that the Company violated Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation.
Violations of the aforementioned provisions are subject to the application of the administrative pecuniary sanction provided for by Article 83, paragraph 5, letter a), and paragraph 4, letter a), of the Regulation, through the issuance of an injunction (Article 18, Law No. 689 of November 24, 1981).
The Guarantor, pursuant to Article 58, paragraph 2, letter i), of the Regulation and Article 166 of the Code, has the power to impose an administrative pecuniary sanction provided for by Article 83, paragraph 5, letter a), and Article 83, paragraph 4, letter a), of the Regulation. 83 of the Regulation, by issuing an injunction (Article 18, Law No. 689 of 24 November 1981) in relation to the processing of personal data carried out by the Company, which has been determined to be unlawful, as set out above.
Considering that it is appropriate to apply Article 83, paragraph 3 of the Regulation, which provides that "If, in relation to the same or related processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement," the total amount of the fine is calculated so as not to exceed the maximum fine set forth in the same Article 83, paragraph 3. 5.
The Authority, in light of Guidelines 4/2022 on the calculation of administrative fines under the GDPR, adopted on May 24, 2023, to which minor amendments were made on June 29, 2023, considers the severity of the breach to be medium, taking into account all relevant factors in the specific case.
In particular, the nature, severity, and duration of the breach were taken into consideration, taking into account the nature, scope, or purpose of the processing in question, as well as the number of data subjects affected by the damage and the level of damage they suffered (see Article 83, paragraph 2, letter a), of the Regulation). Specifically, the duration of the breaches was considered: with regard to the breach of Article 34 of the Regulation, it is noted that the data subjects were notified approximately two months after the Company became aware of the personal data breach; with regard to the breach of Articles 5, paragraph 1, letter b), of the Regulation, the data subjects were notified approximately two months after the Company became aware of the personal data breach. 1, letters e) and f), and 32 of the Regulation, it is noted that the breached authentication credentials had been processed by the Company, in the absence of adequate security measures, for over two years. The significant number of data subjects involved, amounting to 61,670, was also taken into account.
The Authority also took into account the criteria relating to the intentional or negligent nature of the breach and the categories of personal data affected by the breach, as well as the manner in which the supervisory authority became aware of the breach (see Article 83, paragraph 2, letters b) and g), and Recital 148 of the Regulation).
With reference to the other elements listed in Article 83, paragraph 2, of the Regulation, 2 of the Regulation, for the purposes of applying the administrative fine and its quantification, with regard to the Company, considering that the level of severity of the violation is medium, taking into account that the sanction must "in any case be effective, proportionate and dissuasive" (Article 83, paragraph 1 of the Regulation), it is noted that, in this case, the following circumstances were considered:
a) the Company, after becoming aware of the personal data breach, adopted measures that were not adequate to mitigate the risks to the rights and freedoms of data subjects (Article 83, paragraph 2, letter c), of the Regulation);
b) with regard to the degree of responsibility of the controller, the negligent conduct of the Company and its degree of responsibility for failing to comply with data protection legislation with respect to multiple provisions were taken into consideration (Article 83, paragraph 2, letter d), of the Regulation);
c) there are no relevant previous violations committed by the data controller (Article 83, paragraph 2, letter e), of the Regulation);
d) cooperation with the Supervisory Authority has been taken into account (Article 83, paragraph 2, letter f), of the Regulation).
It is also considered that, in this case, taking into account the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the Regulation), the following are of primary importance: the financial circumstances of the offender, determined on the basis of the Company's income statement with reference to the ordinary financial statements for the year 2024, the latest available.
In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative sanction against the Company in the amount of €85,000 (eighty-five thousand).
In this context, it is believed that pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order should be published on the Italian Data Protection Authority's website.
This is in consideration of the type of violations identified, which affected the general principles of processing, the obligation to adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risk, and the obligation to communicate, without undue delay, a personal data breach to data subjects when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
NOW, CONSIDERING ALL THE FOREGOING, THE ITALIAN DATA PROTECTION AUTHORITY
pursuant to Article 57, paragraph 1, letter b) of the Italian Data Protection Authority (Garante). 1.1(f) of the Regulation, finds the processing carried out by The European House - Ambrosetti S.p.A., represented by its legal representative, with registered office at Via Francesco Albani, 21, Milan, Tax Code 09638920158, in accordance with the terms set out in the grounds, unlawful for violation of Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation;
ORDERS
The European House - Ambrosetti S.p.A., pursuant to Article 58, paragraph 2, letter i), of the Regulation, to pay the sum of €85,000.00 (eighty-five thousand/00) as an administrative fine for the violations indicated in this order;
ORDERS
The European House - Ambrosetti S.p.A. to pay the aforementioned sum of €85,000.00 (eighty-five thousand/00), according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—again according to the methods indicated in the attachment—an amount equal to half of the fine imposed, within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below (Article 166, paragraph 8, of the Code);
ORDERS
- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, the publication of the injunction order on the Authority's website;
- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority's Regulation No. 1/2019, the publication of this provision on the Authority's website;
- pursuant to Article 17 of Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2, of the Regulation, in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation.
Pursuant to Article 78 of the Regulations, Articles 152 of the Code, and Article 10 of Legislative Decree No. 150/2011, an appeal against this decision may be lodged with the ordinary judicial authority, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days of the date of notification of the decision, or sixty days if the appellant resides abroad.
Rome, April 17, 2026
THE PRESIDENT
Stanzione
THE REPORTER
Cerrina Feroni
THE SECRETARY GENERAL
Montuori
SEE ALSO Newsletter of May 21, 2026
[web doc. No. 10252460]
Decision of April 17, 2026
Register of Decisions
No. 280 of April 17, 2026
THE ITALIAN DATA PROTECTION AUTHORITY
IN today's meeting, attended by Professor Pasquale Stanzione, President, Professor Ginevra Cerrina Feroni, Vice President, Dr. Agostino Ghiglia, Member, and Dr. Luigi Montuori, Secretary General;
SEEN Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "Regulation");
SEEN the Personal Data Protection Code, containing provisions for the adaptation of national legislation to Regulation (EU) 2016/679 (Legislative Decree No. 196 of June 30, 2003, as amended by Legislative Decree No. 101 of August 10, 2018, hereinafter, the "Code");
HAVING SEEN the preliminary notification of a personal data breach submitted by The European House - Ambrosetti S.p.A. to the Authority on 8 April 2024, pursuant to Article 33 of the Regulation, and the subsequent supplementary notification submitted on 23 May 2024;
HAVING EXAMINED the documentation in the file;
HAVING SEEN the observations made by the Secretary General pursuant to Article 15 of the Garante's Regulation No. 1/2000;
REPORTER: Professor Ginevra Cerrina Feroni;
WHEREAS
1. The Office's investigation into the personal data breach notified pursuant to Article 33 of the Regulation.
The European House - Ambrosetti S.p.A. (hereinafter, the Company), on 8 April 2024, submitted to the Authority, pursuant to Article 33 of the Regulation, 33 of the Regulation, a preliminary notification of a personal data breach, resulting from "data exfiltration following unauthorized access by an attacker" that affected the personal and contact information (email address) and authentication credentials (username and password) of an unspecified number of data subjects.
The Company also stated that "technical investigations are still underway to identify the affected systems in detail" and stated that it had not communicated the personal data breach to the affected data subjects, believing it was not likely to pose a high risk to the rights and freedoms of natural persons.
On April 9, 2024, the Office sent the Company an initial request for information to acquire useful information for assessing the personal data protection aspects. In a note dated April 17, 2024, the Company, while highlighting that it "intends to finalize [the notification] in all its aspects and consequent obligations once the technological investigation activities have been completed, presumably by May 30, 2024," stated, among other things, that:
"134,303 data subjects would be potentially involved. [...] The number is based on a preliminary estimate, but it is presumed to be lower, given that, given Ambrosetti's professional experience, individual data subjects often use different email addresses to authenticate to the services. The Company is carrying out all appropriate checks on this matter" (see note dated April 17, 2024, p. 2);
With the entry into force of the GDPR in 2016, the Company began a process of evaluating and implementing security measures to protect personal data in accordance with the new regulatory provisions. The following is a summary of what has been done to date and its impact on the matter under consideration. In 2018, Ambrosetti began implementing a password management system in web applications, deciding to adopt a password encryption system. Taking into account the state of the art, implementation costs, as well as the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Company therefore identified Bcrypt, one of the main consolidated tools on the market, as the algorithm to be used. Meanwhile, work continued to strengthen the protection systems, initiating the Company's parallel study and feasibility study of a new systemic and application architecture. Therefore, a selection and research activity was launched in 2021, culminating in the introduction of certified systems capable of Offer advanced security services for web applications to meet the needs of increased corporate security. The process being implemented by the Company, starting in January 2022, will only manage the authorization to register on Ambrosetti portals. […] The system automatically sends, to the user's email address provided by the client when establishing the contractual relationship with the Company for the provision of the agreed-upon services between the parties, a dedicated and personal link to the web page from which the user accesses the agreed-upon services, allowing the user to create and manage their own access credentials” (see note cited, p. 3);
"Regarding risk assessments for the rights and freedoms of data subjects, the Committee itself, in its "Guidelines 01/2021 on examples of notification of a personal data breach," clarifies that the proposed case analyses "explicitly refer to those under examination," with the aim of assisting data controllers in assessing data breaches affecting them. However, at the same time, "any change in the circumstances relating to the cases described [...] may result in different or more significant levels of risk, and therefore require different or additional measures," and notification can only be considered "good practice" in some cases. Therefore, assessments that take into account all the concrete elements existing in the specific case under consideration cannot be ignored" (see, cited note, p. 6);
“Ambrosetti, while analyzing the Guidelines and Case 06 referred to [… by] the Authority, in the risk assessment carried out, proceeded to examine in depth the specifics of the case in question, and came to the conclusion, taking into account what is known to date, that the risks to the rights and freedoms of the interested parties are negligible. In fact, from the investigations carried out to date by the Company, it appears that: 1. The exfiltrated data are all access credentials that are currently unusable, relating to systems no longer in use since 2022: starting from 2022, the method of storing access credentials to Ambrosetti systems has in fact changed […]. 2. The files referred to in the notified breach contain Ambrosetti customers' first registration credentials, set by the Company and released to customers after the definition of the contractual relationships governing the provision of training services to the staff agreed with them. It is the user's responsibility to proceed with changing the receipt password, in compliance with the security constraints imposed on the system. Upon expiration of the contract concluded with the Company's client, the students' accounts are automatically deactivated, and this makes it impossible to access Ambrosetti services using said credentials. 3. It also emerged that 96% of the exfiltrated data relates to accounts inactive since 12/31/2023 and, therefore, unusable. With regard to the remaining 4%, following the discovery of the breach in question, the Company promptly imposed the obligation for the user to change their password. Given that this data is therefore obsolete in at least 96% of cases and in any case the credentials are unusable as they relate to systems no longer in use, and since these are first-time registration credentials not set by the user, there are no risks associated with the habit of users using the same or similar password to access other online services. 4. Furthermore […] it also emerged that only "in one case, the passwords were stored in clear text". This is the file called "sgc_login.csv", which appears to be an extraction from a database relating to an application no longer in use since November 18, 2020, and therefore such data is technically not usable to access the Company's services. 5. It should also be noted that the breach essentially does not concern data processed in a business-to-consumer relationship, but rather business-to-business; therefore, the data subjects, pursuant to the law, have received policies from their employers indicating specific precautions for managing passwords used in the performance of their duties, as well as adequate training in this regard. 6. The breach in question concerns initial registration credentials for the Company's websites through which it provides professional training services, and therefore the nature of the sites and the hypothetically accessible data do not generate negative connotations for the data subjects. In fact, no special categories of data are present, such as judicial data or payment data, data revealing membership of a trade union, or data revealing health status” (see note cited, pp. 6, 7);
"Following the discovery of the event, the Company promptly cancelled all passwords for accessing the Ambrosetti systems referred to in the exfiltrated files, requiring active users to update their passwords, in compliance with the security constraints imposed by the Company for accessing its systems" (see note cited, p. 7);
"The Company immediately organized a multidisciplinary team dedicated to the matter, composed of internal ICT representatives, the DPO, and external cybersecurity consultants, which continues to manage and monitor the ongoing investigations" (see note cited, p. 7).
On April 18, 2024, the Office sent the Company a second request for information to acquire further information regarding the personal data breach. It highlighted that, following a technical assessment of the data disseminated online, some of the passwords in question appeared to have been set by the users to whom they referred.
With a note dated April 24, 2024, the Company responded to the aforementioned request for information, stating that:
The authentication credentials disclosed related to the Company's various online services or web applications ("aggiornamentoconoscenza.it", "cocircle.ambrosetti.eu", "fondir.ambrosetti.eu", "healthcare.ambrosetti.eu", "innotechhub.ambrosetti.eu", "live.ambrosetti.eu", "management.ambrosetti.eu", "www.aggiornamentopermanente.it", "www.ambrosetti.eu", "www.ambrosettilive.eu", and "www.leaderdelfuturo.it") (see note dated April 24, 2024, pp. 1-3);
"The aforementioned applications allow potential access only to users who had activated the service provided through the application, making authentication technically impossible for customers who had not purchased the relevant service. All the portals […] referenced only allowed access to training content such as slides, research, and presentations, or registration for events organized by the Company" (see note cited, p. 3);
"The user categories to which the authentication credentials refer are: employees of the Company's customers and employees of the Company. In the AP_USERS-AMBROSETTI.CSV file, the email address contained was not a real one, and therefore, neither directly nor indirectly, allowed the identification of a natural person; rather, it was simply entered as a mandatory field because it was technically required by the application" (see note cited, p. 3);
"The cryptographic functions adopted for each individual file are specified:"
login_users.csv: "MD5 (Message Digest Algorithm 5), a widely used cryptographic hash function supported by a wide variety of software and hardware for calculating the hash of a string or message. It is known for its computational efficiency, simplicity, widespread use, and compatibility, making it a solution compatible with the variety of software and hardware used by the Company at the time."
ldf_users.csv: "The site is developed with Joomla 1.5 and uses MD5 with a 32-character salt added to the end of the password string."
ap_users.csv: "The site is developed with Joomla 1.5 and uses MD5 to hash passwords. When passwords are created, they are hashed with a 32-character salt added to the end of the password string."
chat_users.csv and uni_login.csv: "mixture of MD5 and MD5 with a 32-character salt added to the end of the password string" (see cited note, p. 4);
regarding how the passwords in question were set:
login_users.csv: "The passwords were set by a system administrator when the user was created and can then be changed by the user. Because MD5 encryption is used, it is not technically possible to verify whether the passwords were preset by the administrator or changed by the user."
sgc_login.csv: "The passwords were set by a system administrator when the user was created and can then be changed by the user."
ldf_users.csv and ap_users.csv: "The passwords were set by a system administrator when the user account was created and can then be changed by the user. Since the MD5 cryptographic function with salt is present, it is not technically possible to verify whether the passwords were preset by the administrator or changed by the user."
chat_users.csv and uni_login.csv: "The passwords were set by a system administrator when the user account was created." (see cited note, pp. 4, 5);
One of the Company's web applications ("aggiornamentoconoscenza.it") was discontinued in March 2020, while the other web applications underwent password hashing algorithm updates between February 2020 and October 2022 (see cited note, p. 5);
The Company retains personal data processed in the performance of the activities agreed with customers for ten years following the termination of the relationship with the customer, in order to fulfill regulatory obligations (e.g., tax, accounting) that remain in place even after the termination of the relationship, as well as to enforce the rights arising from the contract in court. To this end, it is noted that the Company, given the type and variety of services provided and the long-standing relationships with its customers, has adopted a commercial practice for managing contractual relationships with customers that tends to favor the definition of framework agreements, which generally govern the relationship between the parties and have an indefinite duration, without prejudice to the right of each party to terminate the relationship with adequate notice, alongside individual offers governing the specific activities requested from time to time. Furthermore, the services provided by the Company are also characterized, by their very nature, by the repetitive nature of requests for similar types of services from the same customer over time (e.g., training services repeated at agreed intervals, but relating to different topics and therefore governed by specific offers), resulting in the continuation of relationships with its customers over time, which therefore requires the retention of their data” (see note cited, p. 6);
“When requesting a new password, the user received the following message: […] It is not recommended to use a password already used in other systems. The password must be at least 8 characters long and include at least one special symbol, one uppercase letter, one lowercase letter, and one number. […] Pending the completion of the ongoing investigations, no further communications have been sent to users to date” (see note cited, pp. 6, 7);
“Only a limited number of customers have requested further information on this well-known matter. In these cases, ad hoc meetings have therefore been held with the respective IT technicians and DPOs, who, to date, have all agreed that the risk has been overlooked” (see note cited, p. 7).
Subsequently, with the supplementary notification dated May 23, 2024, the Company provided further information on the measures taken following the personal data breach and confirmed its nature and scope.
On that occasion, the Company also reiterated that it had not communicated any information to the data subjects pursuant to Article 34 of the Regulation.
Pending the investigation, the Office then assessed the compliance of the measures undertaken by the Company following the breach, with particular reference to compliance with the notification obligations pursuant to Article 34 of the Regulation towards the data subjects to whom the breached authentication credentials refer.
In particular, from examining the information provided, the Garante deemed that the personal data breach in question was likely to pose a high risk to the rights and freedoms of natural persons, contrary to the Company's claims. Therefore, with Order No. 327 of May 23, 2024 (web doc. no. 10037682 at www.garanteprivacy.it), ordered the Company, pursuant to Articles 34, paragraph 4, and 58, paragraph 2, letter e), of the Regulation, to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques.
With the aforementioned order, the Authority also requested the Company to provide adequately documented feedback regarding the steps taken to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques.
In compliance with this, in a note dated June 7, 2024, the Company stated that:
"The communication was made directly to the interested parties for whom the company has an email address. On June 7, 2024, the Company therefore sent the text contained in document Annex 1 – 240607 Communication to Interested Parties to 54,917 interested parties" (see note dated June 7, 2024, p. 1);
In order to ensure similar effectiveness even for data subjects with whom there is no direct contact, the Company has opted for different communication channels, providing:
on 07/06/2024, a dedicated page was published on its company portal, available at this link: https://www.ambrosetti.eu/news/violazione-informatica-in-the-european-house-ambrosetti/
on 07/06/2024, the text of the document (Annex 2 – 240607, Press Release Website) was sent to 25 newspapers, listed in Annex 3 – 240607, List of newspapers sending CS, databreach_070624, for publication on widely distributed channels. (see note cited, p. 1).
On June 12, 2024, the Office sent the Company a third request for information, seeking further information regarding the Company's compliance with the aforementioned order from the Data Protection Authority.
With a note dated June 17, 2024, the Company responded to the aforementioned request for information, stating that:
"The number of data subjects with whom the Company does not have direct contact is 12,709. Due to the necessary manual cleanup and the identification of certain users, this number may be further reduced" (see note dated June 17, 2024, p. 1);
On June 17, 2024, ANSA published the press release sent by the Company in the "paywall" area; "Following the press releases sent to other newspapers, the Company has been actively requesting the publication of the press release since last week. Discussions are currently underway with Corriere della Sera, Il Sole 24 Ore, and Repubblica to agree on a possible further publication" (see note cited, pp. 1, 2);
"In the absence of a direct link between the affected residues not reached by email and their respective companies, we have launched a campaign on TEHA's social media channels" (LinkedIn, Facebook, X, Threads, and Instagram) (see note cited, p. 3);
"The Company has sent a press release containing an incident report to the requesting companies, requesting that they disseminate the incident widely within the Company (e.g., by posting it on the intranet and/or company noticeboard) in order to maximize its awareness among their employees" (see note cited, p. 3).
Subsequently, in a note dated July 3, 2024, the Company provided further updates regarding the additional measures taken to inform the affected parties, stating, among other things, that:
"Ambrosetti sent a detailed statement to 83 of its client companies, employing 11,264 affected parties [...], also requesting that company to widely disseminate the incident internally (e.g., by posting it on the intranet and/or company noticeboard) to maximize its reach among the affected parties. Following the above communication, four companies requested further clarifications, which were provided during videoconference meetings" (see note dated July 3, 2024, p. 1);
"The press release regarding the personal data breach was published in the national newspaper "La Repubblica" on July 1, 2024, on page 14 [...], with a print run of 125,502 and a circulation of 138,093 copies" (see note cited, p. 2);
"On the homepage of the company website, accessible at www.ambrosetti.eu, positioned at the top center and highlighted by an orange frame [...], a specific notice regarding the breach continues to be published, containing a link to the web page where Ambrosetti's news and communications on the matter are available" (see note cited, p. 2);
"TEHA's social media campaign continues" (see note cited, p. 2);
"For the sake of completeness, we hereby announce […] the recent development in the group's corporate reorganization. On July 2, 2020, TEHA Group S.p.A. was established, a company subject to the management and coordination of The European House - Ambrosetti S.p.A., which will be responsible for operational activities" (see note cited, p. 3).
Following its technical assessments, the Office prepared a specific technical report on July 22, 2024, which identified a violation of the obligations under Article 34 of the Regulation in relation to the Company's late notification of the personal data breach to users of its online services whose passwords were stored in clear text or using non-state-of-the-art encryption techniques. Furthermore, the Office identified a violation of the principles of storage limitation and integrity and confidentiality pursuant to Article 5, paragraph 1, letter b) of the GDPR. 166, paragraph 5, of the Code, notifying the Company of the alleged violations of the Regulation, with reference to Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation, for having stored user passwords, either in clear text or using sub-state-of-the-art cryptographic techniques, for having retained the authentication credentials of the same users for certain systems no longer in use, and for having failed to inform the data subjects affected by the personal data breach, as required by law.
In defense briefs dated October 16, 2024, the Company argued that:
- "The breach involved the name, surname, username (corresponding to the email address), and password for accessing Ambrosetti services. The processing of these categories of data is necessary for the performance of the services offered by the Company to its clients (e.g., training, consulting, etc.)" (see note dated October 16, 2024, p. 1);
- "The Company initially did not consider the breach likely to pose a high risk to the data subjects, having in any case, immediately upon discovery, required the change of access credentials to its services, and also initiated an in-depth analysis of the event" (see note cited above, p. 1);
- "Based on the information available at the time, 134,303 data subjects were potentially involved. The analyses conducted by Ambrosetti to date have allowed us to limit the number of data subjects involved to 61,670. By applying a progressive de-duplication process, considering rows referring to the same name/surname and email address as equal, duplicates were eliminated (e.g., users present multiple times, with the same name and surname followed each time by different numbers; users entered multiple times with "Name/dot/Surname", "Name/space/Surname", "NameSurname", "NameSurnameNumber"; email addresses present multiple times, preceded or followed by special characters). This automatic normalization of the fields was followed by a further manual update aimed at eliminating users that could not be traced, either directly or indirectly, to natural persons, such as fictitious users, thus reducing the number of data subjects in this case. The in-depth analyses carried out by the Company in recent months have also allowed us to to specify that 25,705 data subjects whose accounts were archived with unencrypted passwords were involved" (see note cited, pp. 1, 2);
- "following the aforementioned technical analyses, as well as based on the communications exchanged with [… the] Authority, the Company communicated the breach using the methods already detailed. Specifically, the breach notification was sent via email to 54,917 individuals, equal to 89% of the total data subjects in this case. Ambrosetti also informed the data subjects by contacting their client companies where the data subjects work, by publishing a specific banner on the homepage of its website, through dedicated posts on the company's social media channels, and by publishing the press release […] on Ansa.it and in the national newspaper "La Repubblica"" (see note cited, p. 2);
- "The conduct was not intentional because the company was neither conscious nor willing to violate specific laws nor to cause or accept, even potentially, risks to the interested parties" (see note cited, p. 2);
- "The services provided by the Company, by their very nature, are characterized by the repetitive nature of similar requests from its customers for similar types of services from the same customer (e.g., training services repeated at agreed-upon intervals). In response to customer needs for the launch of agreed-upon projects, the Company therefore tends to favor the establishment of agreements initially governing the ongoing relationships between the parties, generally of indefinite duration, alongside individual orders/quotes detailing the activities requested from time to time. As long as the relationships with its customers continue, the processing of their personal data (such as name, surname, email) is therefore necessary for the Company to provide its services" (see note cited, pp. 2, 3);
- "The Company has long been committed to continuously improving the security of its applications and data, including access protection and management, with a view to continually strengthening systemic and application resilience" (see note cited, p. 3);
- "Immediately after the incident was discovered, the obligation to change the access credentials to the Ambrosetti systems contained in the exfiltrated files was imposed, requiring the company to update its passwords, in compliance with the security constraints imposed by the Company for access to its systems. The Company immediately organized a multidisciplinary team dedicated to the matter, composed of internal ICT representatives, the DPO, and external cybersecurity consultants, which continues to manage and monitor the matter to this day. The Company has communicated the incident" (see note cited, p. 3);
- "Since 2016, the Company has begun a process of evaluating and implementing security measures to protect personal data in compliance with the new regulations on personal data, initiating, to this end, the study and feasibility of a new corporate system and application architecture. A selection and research process has therefore begun, culminating in the introduction of certified systems capable of offering advanced security services for web applications to meet the need to increase corporate security. The process being carried out by the Company, starting in January 2022, will only allow users to register on Ambrosetti portals, allowing them to create and manage their own access credentials based on the rules and Access Control Lists (ACLs) defined in the system. [OMISSIS] (see note cited, pp. 3, 4);
- "[OMISSIS]" (see note cited, p. 4);
- "The breach exclusively concerned the identification and access data of the data subjects and did not affect special categories of data." personal” (see note cited, p. 4);
- “the Company became aware of the potential violation from a post published on the social network “X” and, having verified the validity of the information, notified the violation to the Authority” (see note cited, p. 4);
- “during the COVID-19 pandemic, the Company was forced to rapidly modify the methods of providing its services, drastically increasing remote activities, which, from residual, became, given the very nature of Ambrosetti's business, the only possible ones. This led to a consequent exponential increase in requests for the activation of new tools and methods, to be made operational within a much shorter timeframe than the ordinary implementation process the Company had in place, and with reduced staff resources, given the health emergency […]. This emergency situation therefore contributed to the materialization and failure to promptly detect the oversight of 2020, which led to the failure to comply with company procedures, adopted since 2018, which provided (and provide) for the adoption of adequate security measures and the deletion of personal data whose processing is no longer necessary, such as that relating to applications no longer in use, as well as periodic checks on what has been implemented" (see note cited, p. 5).
On December 16, 2024, the Company held a hearing, as requested by the Company. At that time, the party stated that:
- "Regarding the violation of Article 34 of the Regulation, the Company initially decided not to send the notification of the violation to the interested parties, as it was particularly concerned about the potential reputational risks arising from sending such a notification, which would have had a media impact at a time when the Company was busy, on the one hand, organizing the fiftieth edition of the Cernobbio forum, which was held in early September 2024 […] and, on the other, managing a series of changes to its corporate structure (liquidation of one of the residual shareholders from the Ambrosetti family; establishment of TEHA Group S.p.A.; transformation of contracts signed with its employees into permanent contracts)";
- "The Company terminated its relationship with the previous DPO [...], as it believed it had not received adequate training and information from him regarding the rights and obligations established by the Regulation towards the Data Controller, as well as in assessing the risks arising from the personal data breach."
- "The personal data breach occurred through unauthorized access to a database serving approximately ten applications. A SQL injection vulnerability was exploited, which was discovered only post-incident."
- "The development of the aforementioned applications had been entrusted to external personnel initially employed to perform tasks related to the IT system component. With the growing need to rapidly develop a considerable number of applications, due to the ever-increasing importance of online presence following the restrictions imposed to combat COVID-19, these suppliers have also found themselves increasingly involved in the application sphere. The applications managed by the Company have thus grown exponentially during the pandemic, and greater emphasis has been placed on their operational management rather than systematic monitoring of their application security, assuming that security was being performed by the aforementioned suppliers."
- "Following the breach, the Company realized that the external suppliers did not have the adequate skills to develop these applications, also taking into account security and personal data protection aspects."
- "At the time of the personal data breach, improvements had been made to the IT authentication procedures used within the aforementioned applications through the adoption and integration of new IAM (identity access management) systems and the introduction of a second authentication factor";
- "The Company was unaware that user passwords were still stored within the aforementioned database, nor of the technical measures adopted by external providers to protect them";
- "Following the personal data breach, the Company implemented a series of initiatives and investments to adopt additional technical and organizational measures [...], including: the decision to initiate a process to obtain ISO 27001 certification; the termination of contracts with external vendors lacking security expertise for the application development component and after remediation of the identified vulnerabilities; the definition of a procedure for assigning tasks to external ICT vendors that also included an assessment of their cybersecurity skills; the early termination of the contract with the previous DPO [...] and the signing of a different contractual relationship with a new DPO; the provision of training initiatives for staff; and the strengthening of the IT department with the active search for a new manager. [...] The Company has initiated a process of accountability and change regarding personal data protection, which will allow it to better manage any future breaches."
3. The outcome of the investigation and the procedure for adopting corrective and disciplinary measures.
Following an examination of the statements made to the Authority during the proceedings and the documentation acquired, it appears that the Company, as data controller, performed certain processing operations that did not comply with the regulations on personal data protection for the reasons set out below.
In particular, it was established that the Company failed to notify the data subjects of the personal data breach pursuant to Article 34 of the Regulation, despite the breach being likely to pose a high risk to the rights and freedoms of natural persons.
Furthermore, the Company retained user passwords, either unencrypted or using sub-state-of-the-art encryption techniques, and retained the authentication credentials of the same users affected by the breach for certain systems no longer in use.
In this regard, it is noted that, unless the act constitutes a more serious crime, anyone who, in proceedings before the Garante, falsely declares or certifies information or circumstances, or produces false documents or records, is liable pursuant to Article 34 of the Regulation. 168 of the Code "False declarations to the Guarantor and interruption of the performance of the Guarantor's duties or exercise of his powers."
3.1. The applicable regulatory framework.
Article Article 34 of the Regulation provides that "where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay" (paragraph 1), that "the communication to the data subject shall […] describe in clear and plain language the nature of the personal data breach and contain at least the information and the measures referred to in points (b), (c) and (d) of Article 33(3)" (paragraph 2), and that such communication is not required, in particular, if "the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those designed to render the personal data unintelligible to any person who is not authorized to access it, such as encryption" (paragraph 3, letter a).
Article 5, paragraph 1, of the Regulation provides: Article 1(1) of the Regulation establishes that personal data must be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed [...] ('storage limitation')" (letter e)) and must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures ('integrity and confidentiality')" (letter f)).
Article 1(1) of the Regulation Article 32 of the Regulation, concerning the security of processing, further provides that "taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk" (paragraph 1) and that "when assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed" (paragraph 2).
With specific reference to the measures to be implemented when retaining user passwords, the Italian Data Protection Authority (Garante), in collaboration with the National Cybersecurity Agency (AGI), has adopted specific guidelines on password retention (Provision No. 594 of December 7, 2023, web doc. No. 9962283 at www.garanteprivacy.it). These guidelines provide data controllers and processors with guidance and recommendations on state-of-the-art password hashing algorithms, noting, among other things, that: "It is essential that password hashing algorithms meet the following requirements:
a computational complexity such that it is quick to calculate a single digest, but excessively expensive to calculate a large number of them, thus discouraging attackers from attempting to find user passwords;
a memory capacity required such that RAM is saturated when many digests are calculated simultaneously.
For these reasons, when it comes to password hashing, ad hoc algorithms are needed that aim to slow down the attacker's offensive capabilities.” (p. 7).
It was also recalled that “it is strongly discouraged to calculate a digest for password storage through the simple single application of a cryptographic hash function such as those indicated [… in the “Cryptographic Function Guidelines – Hash Functions” adopted by the ACN]” (p. 9).
3.2. Failure to notify data subjects of the personal data breach.
It was first ascertained, based on the findings of the specific technical report drafted on July 22, 2024, that the Company failed to inform the data subjects affected by the personal data breach, amounting to 61,670.
This was because the Company deemed that the personal data breach, affecting the authentication credentials (username and password) of users of its online services, was not likely to pose a high risk to the rights and freedoms of natural persons.
Contrary to the Company's claims, the Italian Data Protection Authority, in its Order No. 327 of May 23, 2024, held that the personal data breach was likely to pose a high risk to the rights and freedoms of natural persons and that the Company should therefore notify the data subjects pursuant to Article 34, paragraph 1, of the Regulation.
This was based on a variety of factors, in particular: the nature of the personal data breach, which occurred as part of a cyber attack aimed at acquiring authentication credentials (username and password, in some cases in the form of a text string, also known as a digest) and other personal data (including name, surname, and email address, in some cases fictitious); The severity and persistence of the potential consequences for natural persons that could arise from the use of the disclosed authentication credentials to unlawfully access computer systems or online services and consult, or acquire, personal data of the data subjects to whom they refer or of other categories of data subjects.
In this regard, it is also necessary to take into account the methods used to set passwords (which, in the absence of evidence to the contrary, should be considered, as a precaution, as if they had been chosen by each user) and the habit of users using the same password, even over time, for the same or other computer systems or online services, or, in any case, using similar passwords with only a few characters changed.
The large number of data subjects to whom the authentication credentials in question refer and the ease with which it is possible to trace specific natural persons, identified or identifiable, from the personal data affected by the breach were also taken into consideration; The low level of security guaranteed by the cryptographic functions used to protect user passwords stored on the Company's systems, in terms of resistance to the most common cyber attacks (e.g., brute force or dictionary attacks) aimed at identifying the password that generated a given digest.
In particular, with regard to this last factor—which must also be assessed in light of the indications and recommendations provided by the Authority in the aforementioned password retention guidelines, prepared in collaboration with the National Cybersecurity Agency—it emerged that some passwords (approximately 98,000) were retained after applying a hashing function (MD5, not always using a salt) that was unable to ensure an adequate level of security, while others (approximately 36,000) were even retained in clear text.
Therefore, with the aforementioned provision of May 23, 2024, the Authority—also taking into account the fact that none of the conditions set forth in Article 34, paragraph 1, of the Italian Legislative Decree were met. 3 of the Regulation, in the presence of which notification to data subjects following a data breach is not required, ordered the Company to communicate the personal data breach to users whose passwords were stored in clear text or using non-state-of-the-art encryption techniques. The Company must describe the nature and potential consequences of the breach in clear and simple language, as well as provide specific guidance on the measures that data subjects can take to protect themselves from any negative consequences of the breach.
Only following the corrective measure adopted by the Authority did the Company inform the data subjects involved in the personal data breach, pursuant to Article 34 of the Regulation, by sending a communication to 54,917 data subjects for whom it had an email address and by making public communications to inform the remaining 12,709 data subjects.
These public communications were made through press releases published on the Company's website and social media channels, and in a national newspaper. They were also sent to several client companies (where numerous interested parties work), with the request to disseminate them widely within their organizations to maximize their awareness among the interested parties involved.
In particular, it emerged that the personal data breach was communicated to the affected data subjects late, compared to the time the Company became aware of it (April 4, 2024). Approximately 55,000 data subjects were informed only on June 7, 2024, through a direct communication, while approximately 13,000 data subjects were informed only through public communications made in June and July 2024.
In this regard, the Company specified that the reason for the delay in communication was that "the Company initially did not consider the breach likely to pose a high risk to the data subjects" (see note 16/10/2024, p. 1) as well as "because of particular concern about the potential reputational risks arising from sending such a communication, which would have had a media impact at a time when the Company was busy organizing the fiftieth edition of the Cernobbio forum, which was held in early September 2024 […] and, on the other hand, to manage a series of changes relating to the corporate structure (liquidation of one of the residual shareholders of the Ambrosetti family; establishment of TEHA Group S.p.A.; transformation of contracts signed with its collaborators into permanent employment contracts)” (see minutes of the hearing of 12/16/2024).
The reasons given by the Company do not justify the delay in submitting the notification pursuant to Article 34 of the Regulation, which was also the result of a corrective measure by the Authority.
Furthermore, it is noted that allowing reputational reasons to prevail over the data subjects' data protection rights represents a clear failure to comply with the principle of accountability, to which the data controller is obliged to conform the processing it performs.
By late notification of the personal data breach, the Company therefore violated the provisions of Article 34 of the Regulation.
3.3. Data security.
During the investigation, it also emerged that, at the time of the personal data breach, some passwords (approximately 98,000) were stored using a hashing function (MD5, not always using a salt), while others (approximately 36,000) were even stored in clear text.
The aforementioned hashing function used, however, is not cryptographically robust, and its use is therefore not an effective measure to protect user passwords. Serious vulnerabilities in this function have been known for several years, allowing the password that generated it to be traced back to a digest.
In this regard, it should be noted that storing passwords using state-of-the-art cryptographic techniques is one of the measures that must be adopted to adequately protect the passwords of users of a computer system or online service.
Storing user passwords in clear text, or using non-state-of-the-art cryptographic techniques, therefore violates Article 5, paragraph 1, letter f), and Article 32 of the Regulation, which, in paragraph 1, letter a), expressly identifies encryption as one of the possible security measures suitable for ensuring a level of security appropriate to the risk (see also Article 83 of the Regulation, which states that "the controller [...] should assess the risks inherent in the processing and implement measures to limit those risks, such as encryption"). The Authority has recently issued a statement to this effect (see Decision No. 759 of 13 November 2024, web doc. No. 10109352 at www.garanteprivacy.it; Decision No. 198 of 11 April 2024, web doc. No. 10013321).
During the investigation, it also emerged that the authentication credentials (and other personal data) involved in the breach "relate to systems no longer in use since 2022." Specifically, the web application "aggiornamentoconoscenza.it" was discontinued in March 2020, while the other web applications to which the aforementioned authentication credentials allowed access underwent password hashing algorithm updates, carried out between February 2020 and October 2022.
In this regard, it should be noted that the retention of authentication credentials (username and password)—taking into account the high risks to the rights and freedoms of natural persons posed by such processing—should be carried out only for the time strictly necessary to achieve the purposes for which such data is processed, such as, for example, verifying the identity of users for access to IT systems or online services or, where applicable, ensuring their security (e.g., storing the most recent passwords set to prevent reuse by the user, so-called password history, or backups to ensure the restoration of the IT authentication system in the event of an incident).
This is also due to the fact that technological progress, over time, may compromise the effectiveness of the technical measures adopted to protect user passwords.
With reference to the Company's statement during the hearing regarding the fact that the application security of the systems was the responsibility of external suppliers and that the Company itself, following the breach, "realized that the external suppliers did not have the adequate skills to develop such applications, also taking into account aspects relating to the security and protection of personal data" (see hearing minutes of 12/16/2026), it is recalled that the Company acted as data controller with respect to the processing operations covered by these proceedings and that, in light of this, and specifically pursuant to Article 4, point 7, of the Regulation, it should have fulfilled the obligations incumbent on the data controller, including the application of the principles of storage limitation and integrity and confidentiality pursuant to Article 5, paragraph 1, letter b). e) and f) of the Regulation, as well as the adoption of the security measures referred to in art. 32 of the Regulation.
Furthermore, it is specified that, where the data controller decides to carry out processing through data processors, it must use only processors providing sufficient guarantees to implement appropriate technical and organizational measures so that the processing meets the requirements of the Regulation and guarantees the protection of the data subject's rights.
It is therefore clear that, in this case, even considering the Company's declarations in this regard, the company itself is at fault (see Article 28 of the Regulation).
The Company has therefore violated Article 5, paragraph 1, letters e) and f), of the Regulation, as well as Article 32 of the Regulation.
4. Conclusions: Declaration of unlawfulness of the processing. Corrective measures pursuant to Article 58, paragraph 2, of the Regulation.
For the above reasons, the Authority believes that the statements, documentation, and reconstructions provided by the data controller during the investigation do not address the concerns notified by the Office in the initiation of the proceedings. Therefore, they are unsuitable for dismissing this proceeding, given that none of the cases provided for in Article 11 of the Garante Regulation No. 1/2019 apply.
The Company's conduct, and specifically the failure to notify the data subjects affected by the personal data breach pursuant to Article 34 of the Regulation, as well as the violation of the obligation to adopt adequate technical and organizational measures to ensure a level of security appropriate to the risk, are unlawful, as set out above, in relation to Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation.
The breach established in the terms set out in the grounds cannot be considered "minor," given the nature of the multiple breaches established, which concerned the general principles of processing as well as the obligation to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk and the obligation to communicate, without undue delay, a personal data breach to data subjects when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
Therefore, given the corrective powers granted by Article 58, paragraph 2 of the Regulation, an administrative fine is imposed pursuant to Article 83 of the Regulation, commensurate with the circumstances of the specific case (Article 58, paragraph 2, letter i) of the Regulation).
5. Adoption of the injunction order for the application of the administrative fine and additional penalties (Articles 58, paragraph 2, letter i) and 83 of the Regulation; Article 83 of the Regulation; 166, paragraph 7, of the Code).
As a result of the proceedings, it is therefore found that the Company violated Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation.
Violations of the aforementioned provisions are subject to the application of the administrative pecuniary sanction provided for by Article 83, paragraph 5, letter a), and paragraph 4, letter a), of the Regulation, through the issuance of an injunction (Article 18, Law No. 689 of November 24, 1981).
The Guarantor, pursuant to Article 58, paragraph 2, letter i), of the Regulation and Article 166 of the Code, has the power to impose an administrative pecuniary sanction provided for by Article 83, paragraph 5, letter a), and Article 83, paragraph 4, letter a), of the Regulation. 83 of the Regulation, by issuing an injunction (Article 18, Law No. 689 of 24 November 1981) in relation to the processing of personal data carried out by the Company, which has been determined to be unlawful, as set out above.
Considering that it is appropriate to apply Article 83, paragraph 3 of the Regulation, which provides that "If, in relation to the same or related processing operations, a controller […] infringes, intentionally or negligently, several provisions of this Regulation, the total amount of the administrative fine shall not exceed the amount specified for the most serious infringement," the total amount of the fine is calculated so as not to exceed the maximum fine set forth in the same Article 83, paragraph 3. 5.
The Authority, in light of Guidelines 4/2022 on the calculation of administrative fines under the GDPR, adopted on May 24, 2023, to which minor amendments were made on June 29, 2023, considers the severity of the breach to be medium, taking into account all relevant factors in the specific case.
In particular, the nature, severity, and duration of the breach were taken into consideration, taking into account the nature, scope, or purpose of the processing in question, as well as the number of data subjects affected by the damage and the level of damage they suffered (see Article 83, paragraph 2, letter a), of the Regulation). Specifically, the duration of the breaches was considered: with regard to the breach of Article 34 of the Regulation, it is noted that the data subjects were notified approximately two months after the Company became aware of the personal data breach; with regard to the breach of Articles 5, paragraph 1, letter b), of the Regulation, the data subjects were notified approximately two months after the Company became aware of the personal data breach. 1, letters e) and f), and 32 of the Regulation, it is noted that the breached authentication credentials had been processed by the Company, in the absence of adequate security measures, for over two years. The significant number of data subjects involved, amounting to 61,670, was also taken into account.
The Authority also took into account the criteria relating to the intentional or negligent nature of the breach and the categories of personal data affected by the breach, as well as the manner in which the supervisory authority became aware of the breach (see Article 83, paragraph 2, letters b) and g), and Recital 148 of the Regulation).
With reference to the other elements listed in Article 83, paragraph 2, of the Regulation, 2 of the Regulation, for the purposes of applying the administrative fine and its quantification, with regard to the Company, considering that the level of severity of the violation is medium, taking into account that the sanction must "in any case be effective, proportionate and dissuasive" (Article 83, paragraph 1 of the Regulation), it is noted that, in this case, the following circumstances were considered:
a) the Company, after becoming aware of the personal data breach, adopted measures that were not adequate to mitigate the risks to the rights and freedoms of data subjects (Article 83, paragraph 2, letter c), of the Regulation);
b) with regard to the degree of responsibility of the controller, the negligent conduct of the Company and its degree of responsibility for failing to comply with data protection legislation with respect to multiple provisions were taken into consideration (Article 83, paragraph 2, letter d), of the Regulation);
c) there are no relevant previous violations committed by the data controller (Article 83, paragraph 2, letter e), of the Regulation);
d) cooperation with the Supervisory Authority has been taken into account (Article 83, paragraph 2, letter f), of the Regulation).
It is also considered that, in this case, taking into account the aforementioned principles of effectiveness, proportionality, and dissuasiveness, which the Authority must adhere to in determining the amount of the fine (Article 83, paragraph 1, of the Regulation), the following are of primary importance: the financial circumstances of the offender, determined on the basis of the Company's income statement with reference to the ordinary financial statements for the year 2024, the latest available.
In light of the above elements and the assessments made, it is deemed appropriate, in this case, to impose an administrative sanction against the Company in the amount of €85,000 (eighty-five thousand).
In this context, it is believed that pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Italian Data Protection Authority (Garante) No. 1/2019, this chapter containing the injunction order should be published on the Italian Data Protection Authority's website.
This is in consideration of the type of violations identified, which affected the general principles of processing, the obligation to adopt appropriate technical and organizational measures to ensure a level of security appropriate to the risk, and the obligation to communicate, without undue delay, a personal data breach to data subjects when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
NOW, CONSIDERING ALL THE FOREGOING, THE ITALIAN DATA PROTECTION AUTHORITY
pursuant to Article 57, paragraph 1, letter b) of the Italian Data Protection Authority (Garante). 1.1(f) of the Regulation, finds the processing carried out by The European House - Ambrosetti S.p.A., represented by its legal representative, with registered office at Via Francesco Albani, 21, Milan, Tax Code 09638920158, in accordance with the terms set out in the grounds, unlawful for violation of Articles 5, paragraph 1, letters e) and f), 32, and 34 of the Regulation;
ORDERS
The European House - Ambrosetti S.p.A., pursuant to Article 58, paragraph 2, letter i), of the Regulation, to pay the sum of €85,000.00 (eighty-five thousand/00) as an administrative fine for the violations indicated in this order;
ORDERS
The European House - Ambrosetti S.p.A. to pay the aforementioned sum of €85,000.00 (eighty-five thousand/00), according to the methods indicated in the attachment, within 30 days of notification of this order, under penalty of the adoption of the subsequent enforcement proceedings pursuant to Article 27 of Law No. 689/1981. Please note that the offender retains the right to settle the dispute by paying—again according to the methods indicated in the attachment—an amount equal to half of the fine imposed, within the deadline set out in Article 10, paragraph 3, of Legislative Decree No. 150 of September 1, 2011, for filing an appeal as indicated below (Article 166, paragraph 8, of the Code);
ORDERS
- pursuant to Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Regulation of the Guarantor No. 1/2019, the publication of the injunction order on the Authority's website;
- pursuant to Article 154-bis, paragraph 3, of the Code and Article 37 of the Authority's Regulation No. 1/2019, the publication of this provision on the Authority's website;
- pursuant to Article 17 of Regulation No. 1/2019, the recording of violations and measures adopted pursuant to Article 58, paragraph 2, of the Regulation in the Authority's internal register provided for by Article 57, paragraph 1, letter u), of the Regulation.
Pursuant to Article 78 of the Regulation, as well as Articles 152 of the Code and 10 of Legislative Decree No. 150/2011, an appeal against this provision may be filed with the ordinary judicial authority, with an appeal filed with the ordinary court of the place identified in the same Article 10, within thirty days from the date of notification of the provision itself, or sixty days if the appellant resides abroad.
Rome, April 17, 2026
THE PRESIDENT
Stanzione
THE REPORTER
Cerrina Feroni
THE SECRETARY GENERAL
Montuori




