TL;DR for the DPO
The weak link was not a firewall: it was two people behind a shop counter, talked into it over the phone by someone claiming to be technical support. The authority charged Arts. 5(1)(f) and 32(1)(b), finding shortcomings in the protection of credentials and digital certificates. Fine: EUR 1,715,600.
The three points that matter
- Article 32 security is not only technology: it includes organisational measures, and staff training is one of them. A successful social engineering attack is also a failure of the instructions given to those who process data under Art. 29.
- System access is not limited to the IT department: it includes retail staff, often employed by third parties. They must be trained, authorised in writing, and given a clear procedure for verifying the identity of anyone requesting remote access.
- Credential and digital certificate management is the technical point charged. Multi-factor authentication, personal rather than shared credentials, prompt revocation: these are the measures that, if documented, can be defended; if absent, they are paid for.
What to do now, in practice
1) Ask clients who can access the systems holding their customers' data, including branches, shops, agents and suppliers: the list is almost always longer than they think; 2) check there is a written procedure for remote access and for verifying the identity of whoever requests it; 3) schedule dedicated training on social engineering, with real examples, and keep the attendance record: it is the evidence that Art. 32 was taken seriously; 4) review multi-factor authentication and credential management; 5) if the client has outlets run by third parties, review the Art. 28 agreements and the instructions given.
Why it matters for your clients
This decision is the best argument for persuading a client to take training seriously. It is not about theory: a well-crafted phone call opened the door to the data of 365,000 people. In smaller companies the typical reaction is 'it won't happen to us, we're small': the answer is that social engineering works best precisely where nobody expects to be a target.
Official source:Italian Data Protection Authority - decision no. 348 of 14 May 2026 (doc. no. 10263796), made public with newsletter no. 549 of 16 July 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free