TL;DR for the DPO
Italian DPA newsletter 16/7/2026: EUR 1.7M to Wind Tre after exfiltration of ~365,000 customers' data. The authority's lens is on the adequacy of measures (Art. 32) and post-incident handling. Also in the newsletter: EUR 50k and 30k to two debt-collection companies, and the principle that customers may obtain the AUDIO of their own support calls (Art. 15 access - Enel case).
The three points that matter
- Exfiltration is not fate: for volumes of hundreds of thousands of data subjects the authority expects measures proportionate to the risk - segmentation, access monitoring, alerts. 'We were attacked' is no defence if measures were below standard.
- Breach handling weighs as much as the breach: detection times, Art. 33 notification, communication to data subjects and transparency towards the authority all enter the fine calculation. A well-kept breach register is the first defensive evidence.
- Art. 15 access covers audio too: if a customer requests the recordings of THEIR support calls, they must be provided. Check clients who record calls: notice, retention and extraction procedure.
What to do now, in practice
1) Use the case in training: it is the argument that unlocks security budgets with reluctant clients; 2) check that the breach register (Art. 33(5)) is current and reasoned - the generator has the ready template, alongside the procedure and the Art. 34 communication; 3) for clients recording calls: a response procedure for audio-access requests, with timing and format.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free