Poste Vita S.p.a.
€80,000
Insufficient technical and organisational measures to ensure information security
Datum der Entscheidung
10. Juli 2025
Behörde
Italian Data Protection Authority (Garante)
IT
Sektor
Finance, Insurance and Consulting
Land
IT
Recht
GDPRStatus
FINALBeschreibung
The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a third party successfully tricking an employee into forwarding sensitive personal data, which was then used against the data subject.
Juristische Zitate
Art. 5 (1)Art. 33 (1)
Probleme und Verstöße
Insufficient technical and organisational measures to ensure information security