Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

740+ Articles
120+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Italian Regulator Fines National Postal Service Orgs $15 Million for Data Privacy Violations
Italian Regulator Fines National Postal Service Orgs $15 Million for Data Privacy Violations
NEWS

Italian Regulator Fines National Postal Service Orgs $15 Million for Data Privacy Violations

Italy's data protection authority fined Poste Italiane €6.6 million and Postepay €5.9 million for illegally processing millions of users' personal data, in one of Italy's largest GDPR enforcement actions of 2026.

Dylan H.

News Desk

April 21, 2026
4 min read

Italy's data protection authority, the Garante per la protezione dei dati personali (Garante), has levied combined fines totaling approximately $15 million (€12.5 million) against two prominent national postal and payments organizations for illegally processing the personal data of millions of users.

The enforcement action targets Poste Italiane SpA — Italy's state-controlled postal services provider — and its digital payments subsidiary Postepay SpA. The Garante fined Poste Italiane €6.6 million ($7.8 million) and Postepay €5.9 million ($7 million), representing one of the largest GDPR enforcement actions against Italian companies in 2026.

What the Garante Found

Italy's data regulator concluded that both organizations had engaged in unlawful personal data processing affecting millions of users. While full details of the Garante's decision have not been published at the time of reporting, the violations are consistent with categories the Garante has historically prioritized:

Violation CategoryDescription
Unlawful processing basisProcessing personal data without a valid legal basis under GDPR Article 6
Consent failuresUsing customer data for marketing or profiling without adequate consent
Data sharingSharing user data with third parties beyond what users agreed to
Transparency failuresInsufficient disclosure to users about how their data is collected and used

Poste Italiane manages one of Italy's largest consumer databases given its role as the national postal operator, while Postepay handles tens of millions of prepaid payment card accounts — making data handling practices at both organizations a significant GDPR risk surface.

Scale of the Issue

The combined fine reflects the broad scope of users potentially affected. Poste Italiane serves virtually every Italian household through postal services, financial products, and telecommunications. Postepay, its fintech arm, operates millions of prepaid cards widely used for online purchases and peer-to-peer transfers — making it one of Italy's most-used digital payment instruments.

With a user base spanning tens of millions, even narrow categories of unlawful processing can represent a significant breach of the rights of large numbers of data subjects under GDPR's risk-based framework.

Context: Italy's GDPR Enforcement Trend

The Garante has been an increasingly active enforcer within the EU's data protection ecosystem. Notable recent actions include:

EntityFineIssue
OpenAI (ChatGPT)€15 millionUnlawful data processing, age verification failures (2024)
Enel Energia€79 millionAggressive telemarketing without consent
TIM (Telecom Italia)€27.8 millionUnlawful marketing calls and data management failures
Poste Italiane / Postepay (2026)~€12.5 millionUnlawful processing of millions of users' data

This enforcement pattern illustrates the Garante's focus on large-scale consumer data holders — particularly utilities, telecoms, and financial services — where the potential for privacy harm is amplified by scale.

Implications for Organizations

The action against two subsidiaries of the same national infrastructure group sends a clear message about intra-group data sharing and subsidiary accountability under GDPR. Regulators increasingly treat corporate groups as collections of independently responsible data controllers rather than a single entity — meaning each entity must maintain its own lawful basis for processing.

Key lessons for data protection practitioners:

  1. Subsidiary independence: Each legal entity in a corporate group must independently satisfy GDPR requirements — even if the group shares data infrastructure
  2. Consent chains: Marketing and profiling activities require fresh, specific consent that survives corporate restructuring and product bundling
  3. Scale amplifies risk: Large consumer datasets attract regulatory scrutiny proportional to the number of data subjects affected
  4. National postal and payments services are explicitly in regulators' crosshairs across the EU

What Happens Next

Both Poste Italiane and Postepay have the option to appeal the Garante's decision before Italian administrative courts. The organizations are likely required to:

  • Cease the specific processing activities identified as unlawful
  • Implement corrective measures to bring processing into GDPR compliance
  • Notify users of the violations and remediation steps where required

Source: The Record — Italian regulator fines national postal service orgs $15 million for data privacy violations

#GDPR#Data Privacy#Italy#Poste Italiane#Postepay#Regulatory Fine#Data Protection

Related Articles

Italian Regulator Fines Financial Giant $36 Million for Data Protection Failures

Italy's data protection authority, the Garante, has fined Intesa Sanpaolo €36 million for serious shortcomings in personal data security, citing...

3 min read

Dutch Court Threatens xAI with Fines Over Grok's Nonconsensual Nude Images

A Dutch court has ordered Elon Musk's xAI to stop generating nonconsensual nude images via Grok or face fines of €100,000 ($115,000) per day for...

5 min read

Pro-Russian Hacktivists Launch Sustained Cyber Campaign

NoName057(16) and allied hacktivist groups are conducting DDoS attacks against Milan-Cortina 2026 Olympic infrastructure, Italian government sites, and...

4 min read
Back to all News