Intesa Sanpaolo Vita S.p.a.

€20,000

Non-compliance with general data processing principles

Datum der Entscheidung

7. Juli 2022

Behörde

Italian Data Protection Authority (Garante)

IT

Sektor

Finance, Insurance and Consulting

Land

IT

Recht

GDPR

Status

FINAL

Beschreibung

The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the DPA against the controller for the unauthorized disclosure of their personal data. In the course of its investigation, the DPA found that the controller had disclosed personal data, such as first name, last name and information about the policy, to third parties without authorization. The unauthorized disclosure had occurred due to an employee's error.

Juristische Zitate

Art. 5 (1)

Probleme und Verstöße

Non-compliance with general data processing principles

Bleiben Sie auf dem Laufenden über die Durchsetzung des Datenschutzes

Wir respektieren Ihre Privatsphäre. Eine E-Mail pro Monat, kein Spam, jederzeit abbestellbar.