​Italian DPA fines UniCredit $3M over data breach GDPR lapses

UniCredit

The Italian data protection authority, Garante, announced a fine of 2.8 million euros (U.S. $3 million) against UniCredit for alleged violations of the General Data Protection Regulation (GDPR) regarding insufficient security measures the bank had in place during a cyberattack.

The penalty, assessed in February but revealed by Garante in a translated newsletter Thursday, came in response to a 2018 data breach at UniCredit that exposed the information of hundreds of thousands of customers.

UniCredit said in an emailed statement it would challenge the regulator’s decision.

lock iconTHIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.