TL;DR for the DPO
Italy's DPA fined The European House - Ambrosetti EUR 85,000 over a data breach affecting 61,670 people (client-company employees and internal staff). Two key findings: 1) part of the passwords was stored in plaintext and another part with cryptographic techniques below the most advanced standards (Art. 32); 2) although the breach was notified to the regulator within 72 hours, the company informed the data subjects only after about two months, and only after a corrective measure, despite the high risk (Art. 34).
The three points that matter
- Notifying the regulator is NOT enough: Art. 33 (72 hours to the authority) and Art. 34 (communication to data subjects when risk is high) are two distinct duties. Here the first was met, the second was not.
- Plaintext passwords = inadequate measures: storing credentials in plaintext or with weak cryptography is a direct breach of Art. 32. Robust password hashing is not optional.
- Timeliness and transparency: warning data subjects two months late deprived them of the chance to protect themselves (e.g. changing compromised passwords). The delay was treated as an aggravating factor.
What to do now
For every client: 1) check HOW passwords are stored (they must be hashed with robust algorithms, never plaintext); 2) prepare an incident-response procedure in advance that clearly separates notification to the authority (72h, Art. 33) from communication to data subjects (Art. 34), and defines WHO decides and BY WHEN; 3) keep data-subject communication templates ready, so that in a high-risk case you act in hours, not months. The Data Breach module with its 72h timer is built for exactly this.
Why it matters for your clients
The fine is modest, but the decision will be widely cited because it targets very common mistakes: poorly managed passwords and a slow, reactive communication to data subjects instead of a planned one. For a DPO it's a chance to run two concrete checks on clients - how credentials are protected and how ready the breach procedure is - before an authority asks the question.
Official source:Italian DPA - Newsletter no. 547 of 21 May 2026 (The European House - Ambrosetti fine)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free