Poste Vita S.p.a.
€80,000
Insufficient technical and organisational measures to ensure information security
결정 날짜
2025년 7월 10일
권한
Italian Data Protection Authority (Garante)
IT
섹터
Finance, Insurance and Consulting
국가
IT
법률
GDPR상태
FINAL설명
The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in a third party successfully tricking an employee into forwarding sensitive personal data, which was then used against the data subject.
법적 인용
Art. 5 (1)Art. 33 (1)
문제 및 위반 사항
Insufficient technical and organisational measures to ensure information security