
Italian Data Protection Authority Sanctions Wind Tre for Data Breaches, Highlighting Cybersecurity in GDPR Compliance
Newscybersecurityprivacyregulationscomplianceprivacy_and_personal_dataaccountabilitybest_practicesdata_breachdata_protectionpersonal_dataDPOvendorsData_Protection_AuthorityGDPRartificial_intelligencepasswordsphishingsocial_engineeringEU
The Italian Data Protection Authority (Garante Privacy) imposed a sanction on Wind Tre for two data breaches, emphasizing that GDPR compliance (specifically Article 32) is now assessed based on the quality of cybersecurity measures. The evaluation focused on credential management, API security, and system resilience as key parameters for regulatory adherence. No specific dates, technical details (e.g., CVE IDs), or breach impacts were disclosed in the notice. The decision highlights the Garante’s shift toward integrating cybersecurity as a core component of GDPR accountability. Wind Tre, a telecommunications provider, was the entity penalized under this enforcement action.