Skip to content

Why the Privacy Authority fined Intesa Sanpaolo twice

All the details on the measures with which the Data Protection Authority sanctioned Intesa Sanpaolo for nearly 50 million euros.

 

Heavy fines from the Privacy Authority to Intesa Sanpaolo.

Here are all the details.

ALL THE PRIVACY AUTHORITY FINES TO INTESA SANPAOLO

The first fine, issued mid-month, is a sanction of 17,628,000 euros “for unlawfully processing the data of about 2.4 million customers unilaterally transferred to the 100% subsidiary Isybank Spa,” while the second, larger in scope, was announced yesterday and amounts to 31.8 million euros “for serious deficiencies in the security of personal data, due to the inadequacy of the technical and organizational measures adopted.” Total, 49.4 million euros. But let’s go in order.

THE ISYBANK CASE

With reference to the first 17.6 million euro fine, the Authority for the protection of personal data chaired by Pasquale Stanzione (in the photo) believes that “To identify among its customers those to be transferred to the newly established Isybank, Intesa Sanpaolo” would have “carried out profiling of the clientele without an appropriate legal basis.”

“In particular – the Privacy Authority states – customers were selected who had certain characteristics, including: age not exceeding 65 years, habitual use of digital channels in the last year, absence of investment products, and financial availability below a certain threshold.”

For the Authority that imposed the sanction, this is “An operation that significantly impacted the position” of the customers, “since it involved the transfer of accounts to a different data controller, with unilateral modification of the contractual conditions and operational methods of the current account compared to those originally provided (e.g., assignment of a new IBAN and consequent need to communicate it to third parties; lack of physical branches and exclusive access via app).”

And that’s not all: “Communications sent to customers to inform them of this operation were also found to be inadequate, mostly sent during the summer period, in the archive section of the Intesa Sanpaolo app, without giving them the necessary prominence that the extraordinary nature of the operation would have required (e.g., through push notifications or SMS).”

According to the Authority, “the processing carried out by the bank in the manner described in the measure is unlawful, also because the customer could not reasonably foresee it based on the context and the information received.” In determining the amount of the sanction, the Authority “took into account the significance of the violations, the high number of customers involved, but also the negligent nature of the infringements and the cooperation provided by the bank.”

THE ACCOUNTS SPIED ON BY COVIELLO

Then comes the 31.8 million euro maxi fine issued in recent hours. In this case, the Authority’s investigation was initiated following the data breach reported by the bank in July 2024 and found that an employee accessed, without justified reason, the banking information of 3,573 customers, making over 6,600 consultations between February 21, 2022, and April 24, 2024. “Such unauthorized accesses were not detected by internal control systems,” the Privacy Authority reiterates, “highlighting significant weaknesses in monitoring and prevention mechanisms.”

Not surprisingly, the Authority speaks of “serious deficiencies in the security of personal data, due to the inadequacy of the technical and organizational measures adopted.” During the investigation, the Authority claims to have ascertained, in particular, “the violation of the principles of integrity and confidentiality of personal data, as well as the principle of accountability, noting the overall inadequacy of the measures adopted. The operational model used, which allowed operators to query the entire customer base with full circulation, was not adequately balanced by controls suitable to prevent and detect unjustified accesses.”

Not only that, because “further critical issues emerged in the management of the data breach. The notification was incomplete and late compared to the deadlines set by the regulations, as was the communication to the data subjects, which occurred only following a previous measure by the Authority on November 2, 2024 (doc. web no. 10070521). These actions compromised the possibility of a timely intervention by the Authority to protect the rights and freedoms of the individuals involved. In light of the violations found, the Authority deemed the conduct carried out by Intesa Sanpaolo unlawful.”

Back To Top