Description

Data Protection Authority opened enforcement proceedings over unlawful processing via BancoPosta and PostePay apps

On 2 April 2025, the Data Protection Authority notified Poste Italiane and PostePay, as joint controllers, of the opening of enforcement proceedings under Articles 58(2) and 83 of the GDPR and Article 166(5) of the Personal Data Protection Code. The Data Protection Authority identified presumed violations of Articles 5, 6, 13, 25, 28, 32 and 35 of the GDPR and Article 122 of the Personal Data Protection Code in relation to the processing of personal data carried out through the BancoPosta and PostePay apps using the ThreatMetrix application. The identified violations concerned the absence of a valid legal basis, the absence of a specific and adequate privacy notice to data subjects, the absence of a data protection impact assessment specific to the ThreatMetrix solution prior to processing, inadequate security measures, failure to respect the data retention limitation principle, and failure to fulfil obligations relating to the designation of the data processor.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-04-16
under deliberation

On 16 April 2024, the Data Protection Authority sent a request for information to Poste Italiane an…

2024-07-17
under deliberation

On 17 July 2024, the Data Protection Authority conducted an inspection at the premises of Poste Ita…

2025-04-02
under deliberation

On 2 April 2025, the Data Protection Authority notified Poste Italiane and PostePay, as joint contr…

2026-04-17
in force

On 17 April 2026, the Data Protection Authority found that Poste Italiane and PostePay, acting as j…