Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

€49.4 Million in Lessons: What Intesa Sanpaolo’s Twin GDPR Fines Mean for Financial Institutions

Contributors

Anas Baig

Product Marketing Manager at Securiti

Rohma Fatima Qayyum

Associate Data Privacy Analyst at Securiti

Published May 14, 2026

Listen to the content

For Intesa Sanpaolo, March has been a costly month for compliance.

It’s not every day that you see GDPR fines imposed on one of the largest banking groups and a major European player. In March, Italy’s Data Protection Authority (Garante) issued two fines on Intesa Sanpaolo:

On March 12, 2026, Garante imposed the first fine, amounting to €17.6 million, on Intesa Sanpaolo for unlawfully processing the data of approximately 2.4 million customers, as it unilaterally transferred the data to its wholly-owned subsidiary Isybank SpA, a fully digital bank. The Garante found that:

  • Intesa Sanpaolo SpA conducted the processing of customer data without an appropriate legal basis. This processing was carried out in relation to the transfer transaction in favor of its subsidiary Isybank SpA.
  • For the purposes of this transaction, Intesa Sanpaolo SpA selected customers who met certain criteria, including: age, which, according to the chosen parameter, could not exceed 65 years of age, familiarity with the digital channels in the last year, the absence of investment products, and financial balances below a certain amount.
  • Customer accounts from Intesa Sanpaolo SpA were transferred to a different data controller (Isybank SpA), leading to a forced alteration of the existing account's operating processes and contractual terms and conditions, in contrast to those originally intended, resulting in new IBANs, a lack of physical branches, and forced access via the mobile application.
  • Customers weren’t informed about this transaction, and the notice was sent to the archive section of the Intesa Sanpaolo SpA mobile application without prompting any push notifications or text messages.

Garante emphasized that the bank's processing in the way specified is unlawful since the customers could not have reasonably anticipated this activity, given the circumstances and the information they were given.

Fine 2: Unauthorized Access to Customer’s Banking Information for Over Two Years

Garante imposed the second fine on Intesa Sanpaolo on  March 30, 2026, amounting to €31.8 million for unauthorized access to the banking information of over 3,500 customers for more than two years. The regulator emphasized that there were serious shortcomings in personal data security due to the inadequacy of the technical and organizational measures adopted.

The Garante found that:

  • An employee accessed, without justification, the banking information of 3,573 customers, making over 6,600 inquiries between February 21, 2022, and April 24, 2024.
  • These unauthorized accesses were not detected by internal control systems, highlighting significant weaknesses in the monitoring and prevention mechanisms.
  • High-risk individuals’ data, such as those with significant public positions, for whom more stringent controls would have been required, was also obtained illegally.
  • This unauthorized access to customers’ personal data violated principles of integrity and confidentiality of personal data, as well as the principle of accountability, noting the overall inadequacy of the measures adopted.

The fines send a stark reminder to the financial institutions, compelling them to honor GDPR requirements or face noncompliance penalties. For Intesa Sanpaolo, this reminder came at a steep price, nudging the banking group to not take customer transparency and internal controls lightly.

Key Takeaways for Financial Institutions

This isn’t the first time Garante has imposed financial penalties. For organizations, this is a learning curve that demonstrates significant compliance gaps existing in the industry today and the critical need to ensure regulatory requirements are met.

Financial institutions must ensure the following:

Customer’s data should not be processed without either obtaining their prior consent or relying on other appropriate lawful basis of processing (i.e., legitimate interest, performance of contract, etc.). Any and all alterations in personal data handling and processing should be promptly notified to the customer, and their consent must be honored. This is particularly important when engaging in profiling. Prior Data Protection Impact Assessments (DPIAs) must be conducted when engaging in large-scale profiling and high-risk processing.

2. Ensure Transparency in Communications

Organizations must provide clear and appropriate notices to customers when processing their personal data. Transparency must be maintained with communications displayed properly, accurately, and in an action-oriented manner.

3. Ensure Data Security, Minimization and Purpose Limitation

Adopt robust security measures, implement access controls through stringent role-based access (RBAC), and the Principle of Least Privilege (PoLP). Organizations should also ensure data confidentiality, integrity, and, most importantly, collect the minimum data required for the originally intended purpose. Moreover, sensitive financial data should not be easily accessible without multi-layered protocols.

4. Implement Robust Detection Systems

Real-time detection of insider risks should be promptly notified, and a culture of continuous monitoring should be embedded across the organization’s data collection, storage, processing, and sharing processes. This helps in early detection of data mishandling and unauthorized access across the data lifecycle, minimizing regulatory exposure and non-compliance penalties.

The most valuable asset a financial institution can have is customer trust. Therefore, operating in hyperscale data ecosystems requires organizations to be one step ahead in regulatory compliance.

Operationalizing GDPR Compliance with Securiti

GDPR compliance requires an automated approach to ensure all regulatory requirements are met, especially when handling large-scale financial data.

Securiti helps financial institutions avoid costly noncompliance fines by:

  • Automating Data Discovery & Access Governance: Identifies where sensitive data lives and enforces role-based, least-privilege access to reduce insider risk.
  • Real-Time Monitoring & Risk Detection: Detects anomalous data access and usage patterns to flag insider misuse early.
  • DPIA & Risk Assessment Automation: Streamlines DPIAs, LIAs, and risk scoring for profiling and high-risk processing.
  • Consent & Preference Management: Ensures valid consent collection and transparency for customer data use, especially profiling.
  • Data Subject Rights Fulfillment: Automates responses to access, deletion, and portability requests at scale.
  • Centralized Compliance & Audit Readiness: Provides evidence, reporting, and accountability dashboards for regulators.

Request a demo to learn more.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
EU AI Act: What Changes Now vs What Starts in 2026 View More
EU AI Act: What Changes Now vs What Starts in 2026
Understand the EU AI Act rollout—what obligations apply now, what phases in by 2026, and how providers and deployers should prepare for risk tiers,...
AI Governance Fails When Privacy Controls Stay Disconnected View More
AI Governance Fails When Privacy Controls Stay Disconnected
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
You Can’t Protect What You Can’t See View More
You Can’t Protect What You Can’t See
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New