Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement May 21, 2026 4 min

Data breach: Italy's DPA fines The European House - Ambrosetti EUR 85,000 over plaintext passwords and late notification

The fine is small, but the findings hit hard: passwords stored in plaintext and data subjects warned two months late. A textbook case on Articles 32 and 34 GDPR

TL;DR for the DPO

Italy's DPA fined The European House - Ambrosetti EUR 85,000 over a data breach affecting 61,670 people (client-company employees and internal staff). Two key findings: 1) part of the passwords was stored in plaintext and another part with cryptographic techniques below the most advanced standards (Art. 32); 2) although the breach was notified to the regulator within 72 hours, the company informed the data subjects only after about two months, and only after a corrective measure, despite the high risk (Art. 34).

The three points that matter

  • Notifying the regulator is NOT enough: Art. 33 (72 hours to the authority) and Art. 34 (communication to data subjects when risk is high) are two distinct duties. Here the first was met, the second was not.
  • Plaintext passwords = inadequate measures: storing credentials in plaintext or with weak cryptography is a direct breach of Art. 32. Robust password hashing is not optional.
  • Timeliness and transparency: warning data subjects two months late deprived them of the chance to protect themselves (e.g. changing compromised passwords). The delay was treated as an aggravating factor.

What to do now

For every client: 1) check HOW passwords are stored (they must be hashed with robust algorithms, never plaintext); 2) prepare an incident-response procedure in advance that clearly separates notification to the authority (72h, Art. 33) from communication to data subjects (Art. 34), and defines WHO decides and BY WHEN; 3) keep data-subject communication templates ready, so that in a high-risk case you act in hours, not months. The Data Breach module with its 72h timer is built for exactly this.

Why it matters for your clients

The fine is modest, but the decision will be widely cited because it targets very common mistakes: poorly managed passwords and a slow, reactive communication to data subjects instead of a planned one. For a DPO it's a chance to run two concrete checks on clients - how credentials are protected and how ready the breach procedure is - before an authority asks the question.

Official source:Italian DPA - Newsletter no. 547 of 21 May 2026 (The European House - Ambrosetti fine)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min