{"id":7145,"date":"2026-04-27T14:08:51","date_gmt":"2026-04-27T14:08:51","guid":{"rendered":"https:\/\/avacysolution.com\/?p=7145"},"modified":"2026-04-27T14:11:14","modified_gmt":"2026-04-27T14:11:14","slug":"guida-profilazione-gdpr-caso-intesa-sanpaolo","status":"publish","type":"post","link":"https:\/\/avacysolution.com\/en\/blog\/news\/guida-profilazione-gdpr-caso-intesa-sanpaolo\/","title":{"rendered":"Profiling and GDPR: compliance lessons from the Intesa Sanpaolo case"},"content":{"rendered":"<p>Until recently, the Data Protection Authority had limited itself to proactive warnings regarding cookie banners and deficient disclosures. However, <strong>the \u20ac17.6 million maxi-fine<\/strong> imposed on <strong>Intesa Sanpaolo case<\/strong> has raised the bar significantly. We are no longer facing simple formal reminders, but rather an inspection intervention that strikes at the heart of digital strategies: the <strong>legal basis<\/strong>.<\/p>\n\n\n\n<p>The core of the issue lies in the balance between business needs and the right to data protection. Specifically, the ruling has put a spotlight on the methods used for <strong>user profiling<\/strong> during the migration to <strong>Isybank <\/strong>and the inadequate adoption of the <strong>accountability principle<\/strong>, challenging the improper use of \"legitimate interest\" where consent was required.<\/p>\n\n\n\n<p>But why does this case represent a point of no return for compliance?&nbsp;<\/p>\n\n\n\n<p>Let\u2019s look in detail at Intesa Sanpaolo\u2019s error and the foundations for <strong>GDPR-compliant<\/strong> <strong>profiling<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Violations found against Intesa Sanpaolo by the Authority<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Using Legitimate Interest instead of Consent<\/strong><\/h3>\n\n\n\n<p>Intesa Sanpaolo based the data transfer and subsequent profiling of customers migrated to Isybank on <strong>legitimate interest<\/strong>. However, the Data Protection Authority ruled that, for activities of such an intrusive nature and for such a radical change to the terms of the contract, this legal basis <strong>was insufficient<\/strong>.<\/p>\n\n\n\n<p>The transition to profiling in digital banking contexts mandates the collection of <strong>explicit consent<\/strong>. Invoking <strong>legitimate interest<\/strong> without a prior balancing of user rights makes the processing unlawful and subject to sanctions.<\/p>\n\n\n\n<p>To learn more: \"<a href=\"https:\/\/avacysolution.com\/en\/blog\/gdpr\/gdpr-consents-everything-you-need-to-know-to-be-compliant\/\">GDPR Consents: Everything You Need to Know to Be Compliant<\/a>\"<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Deficient disclosures and communication methods<\/strong><\/h3>\n\n\n\n<p>The Authority found that the <strong>communications<\/strong> sent to customers were not sufficiently clear. Many users did not understand the implications of moving to Isybank, nor how their <strong>data<\/strong> would be processed for marketing and profiling purposes on the new platform.<\/p>\n\n\n\n<p>Processing compliance is dependent on the presence of a <strong>transparent and accessible information<\/strong>, ensuring the user is fully aware of how their personal data is managed and for what purposes.<\/p>\n\n\n\n<p>To find out more: \"<a href=\"https:\/\/avacysolution.com\/en\/blog\/gdpr\/privacy-policy-compliant-cookie-management-according-to-gdpr-and-eprivacy-directive\/\">Privacy Policy: What It Is and Why It Is Important<\/a>\"<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Lack of a real opportunity to object<\/strong><\/h3>\n\n\n\n<p>In addition to the incorrect legal basis, customers were not provided with a simple and immediate way to object to the transfer or to maintain their previous data management conditions.<\/p>\n\n\n\n<p>According to the law, the GDPR mandates that users must be able to exercise their <strong>right to object<\/strong> easily. Making the transition \"mandatory\" or difficult to refuse violates the principles of <strong>data<\/strong> <strong>self-determination<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Non-granular management of profiling<\/strong><\/h3>\n\n\n\n<p>During the migration, data was processed on a massive scale. Users were not given the option to choose which specific profiling treatments to activate or deactivate within the new digital ecosystem.<\/p>\n\n\n\n<p>A proper profiling <strong>strategy<\/strong> cannot ignore the <strong>granular management<\/strong> <strong>of consent<\/strong>: imposing a \"take it or leave it\" package on personal data fails to respect the criteria for granular consent required by European regulations.<\/p>\n\n\n\n<p>For more information, read: \"<a href=\"https:\/\/avacysolution.com\/en\/blog\/gdpr\/consent-personal-data-processing\/\">Consent for Personal Data Processing for Websites<\/a>\"<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What Are the Risks for Those Who Don't Comply?<\/strong><\/h2>\n\n\n\n<p>The action taken by the Privacy Authority proves that regulatory compliance is no longer an option. With an increasingly proactive approach, those managing databases and digital platforms must ensure they are compliant to avoid devastating consequences:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Economic sanctions:<\/strong> the Intesa Sanpaolo case shows that fines are no longer merely symbolic. The GDPR provides for penalties of up to 4% of total annual global turnover.<\/li>\n\n\n\n<li><strong>Reputational damage:<\/strong> customer trust is a bank\u2019s or company\u2019s most precious resource. A public privacy fine generates a loss of credibility that is difficult to restore.<\/li>\n\n\n\n<li><strong>Blocking of processing:<\/strong> beyond the fine, the Authority can impose an immediate halt on the use of unlawfully collected data, paralyzing sales or customer acquisition operations.<\/li>\n\n\n\n<li><strong>Impact on competitiveness:<\/strong> compliance is an advantage. A company that guarantees security attracts more reliable partners and investors.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to adapt your business to the regulations?<\/strong><\/h2>\n\n\n\n<p class=\"translation-block\">Here are the <strong>key actions<\/strong> to avoid issues:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Review legal bases:<\/strong> evaluate whether legitimate interest is truly applicable or if consent is required.<\/li>\n\n\n\n<li><strong>Total transparency:<\/strong> update disclosures and communications, making them simple, immediate, and transparent.<\/li>\n\n\n\n<li><strong>Granular consent:<\/strong> allow the user to choose exactly what to accept.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Compliance solutions: Avacy's support<\/strong><\/h2>\n\n\n\n<p>Ensuring compliance, especially in complex profiling cases, can be a highly intricate process. Many companies underestimate the configuration of data collection systems, exposing themselves to extreme risks.<\/p>\n\n\n\n<p>This is where <strong>Avacy\u00a0<\/strong>comes in: a professional solution for automating privacy compliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What Avacy offers:<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>GDPR-compliant consent implementation:<\/strong> Avacy allows you to create clear consent collection systems consistent with real data usage, avoiding ambiguous statements.<\/li>\n\n\n\n<li><strong>Advanced and granular management:<\/strong> with Avacy, your site or platform features a system that allows users to accept or reject individual categories of processing (profiling, marketing, etc.).<\/li>\n\n\n\n<li><strong>Continuous monitoring and updates:<\/strong> regulations evolve. Avacy monitors legislative changes and automatically adapts settings to keep your business compliant.<\/li>\n\n\n\n<li><strong>Audit and reporting:<\/strong> It provides tools to prove at any time that consent was collected correctly, which is essential in the event of an inspection by the Authority.<\/li>\n<\/ol>\n\n\n\n<p>Integrating <strong>Avacy\u00a0<\/strong> transforms data management into a competitive advantage,<strong>\u00a0ensuring a transparent user experience<\/strong> and a fluid consent collection system that strengthens customer trust.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<button><a href=\"https:\/\/avacy.eu\/registration\/\">Try Avacy now<\/a><\/button>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p>The <strong>Intesa Sanpaolo case<\/strong> is a lesson for the entire market: the GDPR no longer waits for reports but acts proactively. No entity is too large to be fined if its <strong>legal basis<\/strong> is fragile. Compliance is not just an obligation, but a strategic move to protect your brand value. <strong>Those who do not adapt, risk: now is the time to act<\/strong>.<br><br><\/p>","protected":false},"excerpt":{"rendered":"<p>Fino a qualche tempo fa il Garante della Privacy si era limitato ad ammonimenti proattivi su cookie banner e informative carenti, ma la maxi sanzione da 17,6 milioni di euro inflitta a Intesa Sanpaolo ha spostato l\u2019asticella molto pi\u00f9 in alto. Non ci troviamo pi\u00f9 davanti a semplici richiami formali, ma a un intervento ispettivo&#8230;<\/p>","protected":false},"author":18,"featured_media":7183,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[26],"tags":[],"class_list":["post-7145","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/posts\/7145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/comments?post=7145"}],"version-history":[{"count":31,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/posts\/7145\/revisions"}],"predecessor-version":[{"id":7195,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/posts\/7145\/revisions\/7195"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/media\/7183"}],"wp:attachment":[{"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/media?parent=7145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/categories?post=7145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avacysolution.com\/en\/wp-json\/wp\/v2\/tags?post=7145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}