Article
Insider Threat In Focus: A €31.8m Lesson In Breach Transparency And Risk
An employee at Intesa Sanpaolo unlawfully accessed thousands of customer records over two years, leading to a €31.8 million fine from Italy's data protection authority. The ruling underscores that insider threats demand proactive, risk-based controls and that unauthorised access alone—even without data extraction—triggers serious breach notification obligations under GDPR.
Lewis Silkin