News
๐ฎ๐น Consultation of bank accounts without legal basis
๐ฎ๐น ๐จ A Curious Bank Employee Illicitly Accesses 6,637 Records Over 460 Days
๐ข Order to Inform Clients About Unauthorized Data Access
Source : 10070521
๐ฆ Context
The bank Intesa Sanpaolo discovered that an employee had accessed the data of 9 individuals who were not clients of the branch where he worked.
๐ The employee justified these accesses as mere curiosity.
๐ After an internal audit, the bank terminated his contract.
๐ On July 17, 2024: The bank reported this data breach to the APD, in compliance with Article 33 of the GDPR.
โ ๏ธ Failure to Inform Affected Individuals
๐ The bank ruled that this breach did not pose a high risk to the rights of the affected individuals and did not notify the concerned clients, in violation of Article 34(1) of the GDPR.
๐ New Revelations: 6,637 Unauthorized Accesses
๐
On October 10, 2024, journalistic investigations revealed that the employee had illegally accessed the bank accounts of 3,572 additional individuals between February 2022 and April 2024, including:
- ๐ฉโ๏ธ The sister and ex-partner of the Prime Minister
- ๐๏ธ Ministers, the Senate President, and the National Anti-Mafia Prosecutor
๐ APD Decision
๐ The APD ruled that the bank should have informed the affected individuals.
๐ข In accordance with Article 34(4) of the GDPR and Article 58(2)(e) of the GDPR, the APD ordered the bank to:
โ
Inform affected clients without delay, within a maximum of 20 days.
โ
Ensure that these notifications are made personally by bank employees at the branch where the accounts were opened.
โ
Document these notifications in writing to comply with Article 5(2) of the GDPR.
โ๏ธ Conclusion
โ The bank should have acted sooner to alert clients about these unauthorized accesses.
๐ This case highlights the importance of access controls and transparency in banking data management.