On March 26, 2026, the Italian Data Protection Authority (Garante per la protezione dei dati personali) fined Intesa Sanpaolo S.p.A. EUR 31,800,000, one of the largest fines ever imposed in the Italian banking sector. The proceedings concerned the unlawful processing of data of 2.4 million customers.
What happened
The Authority identified two main issues: the unilateral transfer of customer data to a digital subsidiary (without adequate legal basis and notice), and the poor handling of a data breach, in violation of Articles 33 and 34 GDPR.
On the data breach front, the Garante highlighted that notification to the Authority occurred with significant delay from the time the bank became aware of it. Even after the complete notification (August 30, 2024), the information provided gave only a partial picture of the actual extent of the breach.
The critical point for DPOs
The 72 hours under Art. 33 GDPR is not a suggestion: notification delay is an explicit aggravating circumstance in enforcement. An internal data breach procedure ready to activate is an asset, not a nice-to-have.
Key numbers
What changes for DPOs
- Late notifications are sanctioned more heavily than the breaches themselves
- Subsequent information must be structured (not fragmented)
- Intra-group data transfers always require a documented legal basis
- Art. 6 and Art. 13 GDPR must be verified even in corporate operations
In DPO Workspace
Your client's Data Breach section shows you the 72-hour countdown in real time, with fields already structured for the Authority notification (affected subjects, data categories, consequences, measures taken).
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free