Italy’s Data Protection Authority Criticizes Intesa’s Handling of Customer Data
Italy’s data protection authority has taken a firm stance against Intesa Sanpaolo, the country’s largest bank, accusing it of downplaying the severity of a recent data breach that potentially exposed sensitive information belonging to thousands of customers, including Italy’s Prime Minister Giorgia Meloni. According to Reuters, the authority voiced concerns on Tuesday that Intesa Sanpaolo’s initial response underestimated the risk and scale of the breach, which reportedly involved unauthorized access by a bank employee to around 3,500 client records.
The breach first came to light last month when the authority demanded clarification from Intesa regarding the incident. The bank had confirmed that an employee, who allegedly accessed clients’ personal data without authorization, was suspended pending a criminal investigation. According to the bank, it promptly notified authorities and initiated an internal probe. However, the data protection authority indicated that information about the scope of the breach only emerged through press reports, with full confirmation from Intesa coming much later, according to Reuters.
“Contrary to the bank’s assessment… the breach of the personal data represents a high risk for the rights and freedoms of the individuals concerned,” the authority stated, per Reuters. The watchdog warned that the breach could have significant repercussions for affected customers, potentially impacting their financial status and damaging their reputations.
In its directive, the authority instructed Intesa Sanpaolo to notify all affected customers within 20 days, ensuring transparency regarding any data that might have been exposed. Furthermore, the bank has been ordered to submit a detailed report on its security measures within 30 days, allowing the authority to assess whether its protections for sensitive customer data meet regulatory standards.
In response, Intesa Sanpaolo asserted its commitment to safeguarding customer data. The bank released a statement saying it is actively cooperating with the regulator’s requests and is already enhancing its data protection protocols. “Ensuring the highest level of security for our customers’ data remains a top priority,” the statement read, according to Reuters.
The breach, one of the most prominent in Italy involving sensitive personal and financial data, has intensified calls for improved cybersecurity practices within financial institutions.
Source: Reuters
Featured News
Big Tech Braces for Potential Changes Under a Second Trump Presidency
Nov 6, 2024 by
CPI
Trump’s Potential Shift in US Antitrust Policy Raises Questions for Big Tech and Mergers
Nov 6, 2024 by
CPI
EU Set to Fine Apple in First Major Enforcement of Digital Markets Act
Nov 5, 2024 by
CPI
Six Indicted in Federal Bid-Rigging Schemes Involving Government IT Contracts
Nov 5, 2024 by
CPI
Ireland Secures First €3 Billion Apple Tax Payment, Boosting Exchequer Funds
Nov 5, 2024 by
CPI
Antitrust Mix by CPI
Antitrust Chronicle® – Remedies Revisited
Oct 30, 2024 by
CPI
Fixing the Fix: Updating Policy on Merger Remedies
Oct 30, 2024 by
CPI
Methodology Matters: The 2017 FTC Remedies Study
Oct 30, 2024 by
CPI
U.S. v. AT&T: Five Lessons for Vertical Merger Enforcement
Oct 30, 2024 by
CPI
The Search for Antitrust Remedies in Tech Leads Beyond Antitrust
Oct 30, 2024 by
CPI