Cybersecurity Policy Report, Postal Service, Bank Fined Over Privacy Violations in Italy, (Apr 21, 2026)
By Tony Foley
Garante, the Italian data protection authority, has levied fines totaling more than 12 million euros ($14.1 million) against Italy’s postal service and a bank over mobile banking applications that processed personal information of users in violation of the European Union’s General Data Protection Regulation (GDPR).
Following numerous reports and complaints received by the agency since April 2024, Garante’s investigation into Poste Italiane SpA and PostePay SpA focused on the operating methods of their BancoPosta and Postepay apps. The apps required users to authorize the monitoring of a series of data contained on mobile devices, including installed and running apps, to identify any malicious software, according to a press release yesterday from the agency. The companies asserted that the processing was necessary to ensure the security of transactions and to comply with payment service regulations.
In its decision handed down last week, Garante found that the methods adopted by the company entailed an excessively invasive interference in the private sphere of app users, holding that they were not strictly necessary for the purpose of fraud prevention. In addition, Garante identified numerous violations of personal data legislation, including deficiencies in the information provided to users, the absence of an adequate data protection impact assessment, failure to adopt adequate security measures and appropriate data retention policies, and irregularities in the designation of the data controller.
In addition to fines of 6.6 million euros ($7.75 million) against Poste Italiane and 5.9 million euros ($6.93 million) against PostePay, Garante ordered the companies to cease the contested processing, comply with specified data retention requirements, and notify the agency regarding their compliance measures.
News: InternationalLegislation LitigationEnforcement DataPrivacy DataSecurity GDPR