Description

Data Protection Authority conducted inspection over unlawful processing via BancoPosta and PostePay apps

On 17 July 2024, the Data Protection Authority conducted an inspection at the premises of Poste Italiane under Articles 58(1)(a), (e) and (f) of Regulation (EU) 2016/679 (GDPR) and Articles 157 and 158 of Legislative Decree No. 196/2003 (the Personal Data Protection Code). The inspection established that the ThreatMetrix library, integrated into the Integrated Anti-Fraud Platform, collected MD5 hash codes of applications running on users' Android devices and transmitted them to the sub-processor's cloud systems. The inspection further established that the ThreatMetrix console displayed a "malicious installed apps" attribute listing identified malicious applications as MD5 hash strings. Data retention in ThreatMetrix systems was confirmed at six months. At the time of the inspection, 5.97 million BancoPosta app installations and 8.6 million PostePay app installations were recorded on Android devices.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-04-16
under deliberation

On 16 April 2024, the Data Protection Authority sent a request for information to Poste Italiane an…

2024-07-17
under deliberation

On 17 July 2024, the Data Protection Authority conducted an inspection at the premises of Poste Ita…

2025-04-02
under deliberation

On 2 April 2025, the Data Protection Authority notified Poste Italiane and PostePay, as joint contr…

2026-04-17
in force

On 17 April 2026, the Data Protection Authority found that Poste Italiane and PostePay, acting as j…