Description

Data Protection Authority announced investigation over unlawful processing via BancoPosta and PostePay apps

On 16 April 2024, the Data Protection Authority sent a request for information to Poste Italiane and PostePay following 140 reports and 12 complaints received in April and May 2024. The complaints concerned the processing of personal data of users of the BancoPosta and PostePay apps installed on Android operating systems. Users had been presented with a message requiring them to authorise the apps to access usage data to detect malicious software. The message stated that this authorisation was mandatory and that failure to activate it would limit app access to a maximum of three logins, after which app functionality would be suspended.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-04-16
under deliberation

On 16 April 2024, the Data Protection Authority sent a request for information to Poste Italiane an…

2024-07-17
under deliberation

On 17 July 2024, the Data Protection Authority conducted an inspection at the premises of Poste Ita…

2025-04-02
under deliberation

On 2 April 2025, the Data Protection Authority notified Poste Italiane and PostePay, as joint contr…

2026-04-17
in force

On 17 April 2026, the Data Protection Authority found that Poste Italiane and PostePay, acting as j…