Italy: Data Protection Authority investigation into Poste Italiane and PostePay over alleged unlawful processing via BancoPosta and PostePay apps

Progress

Current status
in force
17 Apr 2026 in force
02 Apr 2025 under deliberation
17 Jul 2024 under deliberation
16 Apr 2024 under deliberation

Scope

Implementers
Italy
Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies)
other service provider
Government Branch
executive
Government Body
data protection authority
Implementation Level
national

Timeline of events

17 Apr 2026
in force

Data Protection Authority issued fines totalling EUR 12.5 million and ordered cessation of processing via BancoPosta and PostePay apps

On 17 April 2026, the Data Protection Authority found that Poste Italiane and PostePay, acting as joint controllers, had unlawfully processed personal data of millions of customers via the BancoPosta and PostePay applications, in breach of Articles …

Source
Event type investigation
Action type ruling
Government branch executive
Government body data protection authority
02 Apr 2025
under deliberation

Data Protection Authority opened enforcement proceedings over unlawful processing via BancoPosta and PostePay apps

On 2 April 2025, the Data Protection Authority notified Poste Italiane and PostePay, as joint controllers, of the opening of enforcement proceedings under Articles 58(2) and 83 of the GDPR and Article 166(5) of the Personal Data Protection Code. The…

Source
Event type investigation
Action type announcement
Government branch executive
Government body data protection authority
17 Jul 2024
under deliberation

Data Protection Authority conducted inspection over unlawful processing via BancoPosta and PostePay apps

On 17 July 2024, the Data Protection Authority conducted an inspection at the premises of Poste Italiane under Articles 58(1)(a), (e) and (f) of Regulation (EU) 2016/679 (GDPR) and Articles 157 and 158 of Legislative Decree No. 196/2003 (the Persona…

Source
Event type investigation
Action type announcement
Government branch executive
Government body data protection authority
16 Apr 2024
under deliberation

Data Protection Authority announced investigation over unlawful processing via BancoPosta and PostePay apps

On 16 April 2024, the Data Protection Authority sent a request for information to Poste Italiane and PostePay following 140 reports and 12 complaints received in April and May 2024. The complaints concerned the processing of personal data of users o…

Source
Event type investigation
Action type announcement
Government branch executive
Government body data protection authority