started · updated
Italian banks face scrutiny over data privacy and unauthorized account access
Italian authorities have concluded investigations into two separate banking sector incidents involving data privacy and unauthorized access.
In Bari, prosecutors have notified an ex-employee of Intesa Sanpaolo, Vincenzo Coviello, of the conclusion of preliminary investigations. Coviello is accused of systematically accessing the private accounts of 3,572 customers between January 2020 and April 2024. The investigation revealed that the employee used his operational credentials to conduct covert monitoring of sensitive financial data, including the accounts of high-ranking state officials such as President Sergio Mattarella.
Separately, the Italian Data Protection Authority (Garante) has fined BBVA 5.5 million euros for privacy violations. The sanction follows the bank's failure to stop promotional messages to a customer who had explicitly opted out via both the bank's app and customer service. BBVA attributed the seven-month lapse to a CRM software malfunction. The regulator also noted that the bank failed to respond to formal complaints within the timeframe required by GDPR and provided incorrect information regarding its data processing practices.
Entities
BBVA · Garante per la protezione dei dati personali · Intesa Sanpaolo · Sergio Mattarella · Vincenzo Coviello