Finance

Italy data protection agency fines Intesa Sanpaolo $36 million over data breach

Published by Global Banking & Finance Review

Posted on March 30, 2026

2 min read

· Last updated: April 1, 2026

Add as preferred source on Google
Italy data protection agency fines Intesa Sanpaolo $36 million over data breach
Global Banking & Finance Awards 2026 — Call for Entries

MILAN, March 30 (Reuters) - Italy's data protection authority said on Monday it had fined the country's biggest bank Intesa Sanpaolo 31.8 million euro ($36.41 million) over a data breach case that

Italy data protection agency fines Intesa Sanpaolo $36 million over data breach

Details of the Intesa Sanpaolo Data Breach and Fine

Overview of the Incident

MILAN, March 30 (Reuters) - Italy's data protection authority said on Monday it had fined the country's biggest bank Intesa Sanpaolo 31.8 million euro ($36.41 million) over a data breach case that involved some 3,500 customers over two years.

Extent of Unauthorized Access

According to the agency's investigation, an Intesa employee accessed banking information of 3,573 customers, carrying out more than 6,600 consultations between February 2022 and April 2024.

Internal Control Failures

"These unauthorised accesses went undetected by the bank’s internal control systems, revealing significant weaknesses in its monitoring and prevention mechanisms," the authority, known in Italy as the 'Garante', said in a statement.

Response and Consequences

Bank's Reaction

Intesa Sanpaolo did not immediately respond to a request for comment.

Impact on Customers

Among the clients affected were individuals with prominent public roles for whom enhanced control measures should have been in place, the Garante said.

Corrective Measures and Fine Calculation

In setting its fine, the authority said it took into account corrective measures subsequently adopted by the bank to strengthen its internal control systems and data security safeguards.

Additional Information

($1 = 0.8734 euros)

(Reporting by Elvira Pollina, editing by Cristina Carlevaro and Gavin Jones)

Key Takeaways

  • The Garante emphasised Intesa’s failure to promptly report the breach involving 3,500 clients, including high‑profile individuals, violating GDPR obligations (dig.watch)
  • The fine (€31.8 million) reflects both punitive and corrective intent, underscoring heightened scrutiny of internal data controls within major financial institutions (dig.watch)
  • This penalty follows an earlier €17.6 million fine imposed in March 2026 for unlawful processing of data of 2.4 million customers transferred to Isybank, indicating repeated compliance concerns (ansa.it)

References

Frequently Asked Questions

Why was Intesa Sanpaolo fined by Italy's data protection authority?
Intesa Sanpaolo was fined for a data breach that affected around 3,500 customers over two years.
How much was the fine imposed on Intesa Sanpaolo?
The fine was 31.8 million euros, equivalent to about $36.41 million.
How many Intesa Sanpaolo customers were affected by the data breach?
Approximately 3,500 customers were involved in the data breach.
Who reported the fine against Intesa Sanpaolo?
The fine was announced by Italy's data protection authority and reported by Reuters.
Over what period did the Intesa Sanpaolo data breach occur?
The data breach spanned a period of two years.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category