Description
Data Protection Authority issued fines totalling EUR 12.5 million and ordered cessation of processing via BancoPosta and PostePay apps
On 17 April 2026, the Data Protection Authority found that Poste Italiane and PostePay, acting as joint controllers, had unlawfully processed personal data of millions of customers via the BancoPosta and PostePay applications, in breach of Articles …
Scope
Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority
Complete timeline of this policy change
Hide details
2024-04-16
under deliberation
2024-07-17
under deliberation
2025-04-02
under deliberation