Organization
Garante
Italy's data protection authority, responsible for GDPR supervision and the Intesa Sanpaolo insider data-breach sanction.
What to know first
- IdentityGarante, Government agency, Government bodyHigh confidence
- People and linksUnavailable: Intesa Sanpaolo, Policy, Italy fines Intesa Sanpaolo EUR31.8m over insider data breachMedium confidence
Basic information
- Display nameGaranteHigh confidence
- Legal typeGovernment agencyHigh confidence
- Directory categoryGovernment bodyHigh confidence
- AliasesItalian Data Protection Authority, Garante Privacy, GPDPMedium confidence
- Last updatedAug 28, 2026High confidence
Locations
- Geography scopeItalyHigh confidence
- Other infrastructure servicesItalyMedium confidence
Other network resources
- Service platformGarante Other infrastructure services · ItalyHigh confidence
People and contacts
- ContactsPolicyMedium confidence
- Available contact typesPolicyMedium confidence
Source basis
- Garante press release on Intesa Sanpaolo EUR31.8m data-breach sanctionItaly's data protection authority said it fined Intesa Sanpaolo EUR31.8 million after an employee accessed banking information for 3,573 customers in more than 6,600 consultations between February 21, 2022 and April 24, 2024, with internal controls failing to detect the accesses.High confidence
- Garante decision of March 26, 2026 on Intesa SanpaoloThe Garante decision declared Intesa Sanpaolo's conduct unlawful for violations of GDPR Articles 5, 24, 32, 33 and 34, describing broad internal query capability, late and incomplete notification and the need for stronger ex-ante authorization, ex-post controls and data masking.High confidence
- Intesa Sanpaolo official group profileIntesa Sanpaolo describes itself as one of Europe's top banking groups, Italy's leader across business areas, serving approximately 14 million customers in Italy through more than 2,600 branches.High confidence
- Reuters report mirrored by MarketScreener on Intesa Sanpaolo fineReuters reported the EUR31.8 million sanction as a major enforcement action against Italy's biggest bank and quoted the regulator's finding that unauthorized accesses went undetected by internal controls.High confidence
- Lewis Silkin analysis of Intesa Sanpaolo insider-threat enforcementLewis Silkin analyzed the decision as an insider-threat control and breach-transparency case, highlighting that viewed-only banking data and incomplete notification still created GDPR exposure.High confidence
