The Italian Data Protection Authority (Garante), through its decision of 10 July 2025, imposed a fine for the inadequacy of preventive security measures and for the delayed notification of a breach involving the unlawful disclosure of personal data to an unauthorized third party (data breach), despite the incident having been caused by a well-orchestrated fraud.
This case, which came to light following a complaint, highlights the need to:
- adopt thorough procedures for verifying the requester’s identity (i.e., adequate preventive measures regarding the origin of the breach, especially in sensitive contexts),
- implement appropriate measures to ensure awareness of the data breach,
- determine precisely the moment of such awareness and document it properly,
- ensure the prompt management of personal data breaches together with notification to the Garante and communication to the data subjects (where required), as provided for by the GDPR.
Facts
The Garante’s decision of 10 July 2025 (web document no. 10154110) concerned the following factual circumstances.
Ms. XX lodged a complaint alleging that Poste Vita S.p.A. had unlawfully disclosed detailed information and documentation regarding three of her life insurance policies to an unauthorized third party. This third party then used the data in legal proceedings against her. The information and documents had been sent to a “German email address” of the requester, which the complainant had never created or used.
Since the timeliness of the controller’s reaction was also at issue, the chronology of events is of particular importance.
Poste Vita responded to the complaint by explaining that it had received several email requests between 2021 and 2023 from an account bearing the complainant’s name. These requests contained the complainant’s handwritten signature and precise details about her additional payments and postal savings account, elements which had led staff to believe that they came from a party entitled to access the information.
Only later, following a formal repudiation of the requests by Ms. XX (22 September 2024), did Poste Vita learn of the fraud and initiate internal investigations, suspending communications to the disputed email address.
Following a complaint dated 16 December 2024 from Ms. XX’s legal counsel, which revealed that the data had been filed in court proceedings by the complainant’s nephew, on 20 January 2025, at the conclusion of its internal investigation, the company notified the Garante of the personal data breach.
Poste Vita filed a criminal complaint against persons unknown on 7 February 2025.