Bank fined €31.8M after employee snooped on accounts
The Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for serious shortcomings in personal-data security. An employee accessed 3,573 customers' banking records without justification from Feb 2022 to Apr 2024, making over 6,600 consultations. The regulator found internal monitoring failed to detect the abuse and said notifications to affected customers were incomplete and late, including high‑risk public‑figure accounts.
Italian regulator fines financial giant $36 million for data protection failures
The Italian Data Protection Authority fined Intesa Sanpaolo SpA for what it called “serious shortcomings in personal data security, due to the inadequacy of the technical and organizational measures adopted.”