Skip to content

Two Fines. Same Bank. Same Root Cause: Data Governance Gaps at Scale.

April 3, 20262 minute read

If you think compliance risk sits only in cybersecurity… you’re already exposed.

In March, Intesa Sanpaolo was hit twice by the Garante per la protezione dei dati personali—for very different failures, but with a single underlying message:

1. Strategic failure: data migration without legal control (€17.6M)
During a large-scale migration to its digital entity (Isybank), the bank:
→ Profiled ~2.4M customers (age, usage, financial data)
→ Transferred them without valid legal basis
→ Failed to properly inform users
Translation: Your transformation programs (cloud, AI, digital spin-offs) are now regulatory events.

2. Operational failure: insider access left unchecked (€31.8M)
In parallel, an internal breach exposed:
→ 6,600+ unauthorized data accesses
→ Over 2 years, by an employee
→ With no effective detection or escalation
Translation: Your biggest data risk is often inside—and invisible without continuous monitoring.

The real takeaway: This isn’t about GDPR theory anymore.
It’s about execution failure across two fronts:
→ Strategic layer → data flows, profiling, cross-entity transfers
→ Operational layer → access control, monitoring, auditability
And regulators are now stacking penalties across both.

What this means?
If you cannot:
• Map and justify why data moves
• Prove who accesses what, when, and why
• Continuously assess data sovereignty risks
You are not compliant. You’re just hoping.

The Shift
Compliance is no longer a legal checkbox.
It’s a data control system.

At S8fe.ai, we help you:
• Classify and label sensitive data at scale
• Control and justify cross-border and intra-group data flows
• Detect and audit risky access patterns in real time

If your compliance posture can’t withstand both strategic transformation and operational scrutiny, it’s time to fix it.

Sources:
• https://www.reuters.com/business/finance/italy-fines-intesa-sanpaolo-18-mln-euros-illicit-processing-customer-data-2026-03-12/
• https://www.reuters.com/sustainability/boards-policy-regulation/italy-data-protection-agency-fines-intesa-sanpaolo-36-mln-over-data-breach-2026-03-30/

Share this article

Back To Top