
Summary The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the DPA against the controller for the unauthorized disclosure of their personal data. In the course of its investigation, the DPA found that the controller had disclosed personal data, such as first name, last name and information about the policy, to third parties without authorization. The unauthorized disclosure had occurred due to an employee’s error.
Link: link
Related articles:  Art. 5 (1) a), f) GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 20,000
Sector Finance, Insurance and Consulting


All data is based on The CMS’s Law GDPR Enforcement Tracker Source:

Tags: case law