Intesa Sanpaolo Fined €31.8M Over Employee Snooping
An Intesa Sanpaolo employee accessed 3,573 customers' banking data without justification between Feb 2022 and Apr 2024. The Italian Data Protection Authority found weak technical and organizational controls and failed monitoring of privileged access. The regulator also cited late and incomplete notifications to affected customers, including high‑risk public figures, and imposed a €31.8 million fine.
Italian regulator fines financial giant $36 million for data protection failures
The Italian Data Protection Authority fined Intesa Sanpaolo SpA for what it called “serious shortcomings in personal data security, due to the inadequacy of the technical and organizational measures adopted.”