All news
Enforcement March 26, 2026 4 min

Intesa Sanpaolo: 31.8M euro fine from the Italian DPA

March 26, 2026 decision: data breach handled late and incompletely

On March 26, 2026, the Italian Data Protection Authority (Garante per la protezione dei dati personali) fined Intesa Sanpaolo S.p.A. EUR 31,800,000, one of the largest fines ever imposed in the Italian banking sector. The proceedings concerned the unlawful processing of data of 2.4 million customers.

What happened

The Authority identified two main issues: the unilateral transfer of customer data to a digital subsidiary (without adequate legal basis and notice), and the poor handling of a data breach, in violation of Articles 33 and 34 GDPR.

On the data breach front, the Garante highlighted that notification to the Authority occurred with significant delay from the time the bank became aware of it. Even after the complete notification (August 30, 2024), the information provided gave only a partial picture of the actual extent of the breach.

The critical point for DPOs

The 72 hours under Art. 33 GDPR is not a suggestion: notification delay is an explicit aggravating circumstance in enforcement. An internal data breach procedure ready to activate is an asset, not a nice-to-have.

Key numbers

31.8MEUR
Total fine
2.4M
Customers affected
72h
Notification deadline (Art. 33)

What changes for DPOs

  • Late notifications are sanctioned more heavily than the breaches themselves
  • Subsequent information must be structured (not fragmented)
  • Intra-group data transfers always require a documented legal basis
  • Art. 6 and Art. 13 GDPR must be verified even in corporate operations

In DPO Workspace

Your client's Data Breach section shows you the 72-hour countdown in real time, with fields already structured for the Authority notification (affected subjects, data categories, consequences, measures taken).

Official source:Decision of March 26, 2026 (Garante)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min