Italian Garante Fines Bank 600,000 Euros for Pre-GDPR Data Breach
Time 1 Minute Read

The Italian Data Protection Authority (Garante per la protezione dei dati personali, “Garante”) recently announced that it levied a €600,000 fine on banking institution UniCredit for several violations of the Italian Personal Data Protection Code, in its pre-General Data Protection Regulation (“GDPR”) form.

The sanction was imposed following a data breach that took place between April 2016 and July 2017 that the banking institution notified to the Garante at the end of July 2017. As a result of the breach, the personal data of over 700,000 customers, including contact details, employment data (e.g., salary information), education data, identification details and financial data (e.g., bank account number, information on loans, payment status and customers’ credit ratings), was unlawfully accessed.

The Garante found that the bank had failed to implement adequate security measures and comply with local requirements regarding the tracking of banking transactions. In determining the amount of the fine, the Garante took into account the number of individuals affected by the breach, as well as the fact that the bank had implemented various security measures to strengthen the security of its IT systems following the breach.

Read the Garante’s decision (in Italian).

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Time 1 Minute Read

On June 19, 2025, the UK Data (Use and Access) Act 2025 received Royal Assent. The same day, the UK Information Commissioner’s Office published a comprehensive suite of resources on the Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page