Sharp response from Poste Italiane to the fine received from the Privacy Authority. Here are all the details.
THE FINE FROM THE AUTHORITY TO POSTE
A fine of 12.5 million euros imposed by the Privacy Authority chaired by Pasquale Stanzione (in the photo). Specifically, a sanction of 6,624,000 euros to Poste Italiane S.p.A. and a slightly lower one of 5,877,000 euros to Postepay S.p.A.
ARE POSTE’S APPS NOSY?
The matter was already known and had been examined by the Antitrust Authority and the Lazio Regional Administrative Court and concerns in particular the operating methods of the BancoPosta and Postepay apps. The Authority did not like that these applications required, as a mandatory condition for using the services, “the release by users of an authorization to monitor a series of data contained in mobile devices, including installed and running applications, in order to identify any malicious software.”
THE ACCUSATIONS OF THE AUTHORITY AGAINST POSTE ITALIANE
According to the companies, such processing was necessary to ensure the security of operations and comply with the regulations on payment services. However, the Authority “noted that the methods adopted involved an excessively invasive interference in the private sphere of users, as they were not strictly necessary for the purposes of fraud prevention.”
During the investigation, several violations of personal data protection regulations also “emerged, including deficiencies in the information provided to users, lack of an adequate data protection impact assessment (DPIA), failure to adopt adequate security measures and suitable data retention policies, as well as irregularities in the appointment of the data controller.”
In addition to the sanction, the Authority ordered the companies to cease the contested processing, if they had not already done so, and to comply with the data retention requirements, notifying the Authority accordingly.
POSTE’S SHARP REPLY
The reply from the group led by Matteo Del Fante was prompt. Poste Italiane “welcomes with surprise the measure by which the Privacy Authority imposed a sanction for an alleged unlawful processing of personal data of BancoPosta and PostePay users.”
“A measure which – say Poste – is flawed not only on the merits but also procedurally, having been adopted in clear delay beyond the mandatory deadlines set by law for the exercise of the Authority’s powers.”
THE PRECEDENT WITH THE ANTITRUST AND THE DECISION OF THE TAR
“In this regard, it is noted that on February 2, 2026, the Lazio Regional Administrative Court annulled the measure by which the Antitrust Authority had sanctioned Poste Italiane for an alleged unfair commercial practice related to the same anti-fraud device subject to today’s criticisms by the Authority, recognizing its full legitimacy and the absence of any commercial intent in Poste’s conduct,” it is added as a precedent to be taken into account.
THE ANNOUNCEMENT OF AN IMMEDIATE APPEAL TO OBTAIN ANNULMENT
Poste Italiane “therefore rejects all charges and reiterates the correctness and transparency of its operations. In particular, as also recognized by the Bank of Italy, the Group has legitimately and in compliance with the regulations on payment services used access to the technical data of customers’ devices, aimed exclusively at activating anti-fraud and anti-malware measures, as required by European legislation [on payment systems, PSD2 Directive editor’s note], for full protection of user security.”
Poste Italiane, the statement concludes, “will file an appeal for the annulment of the measure with the Court of Rome.”




