GDPR Article 32: a small Italian fine, big obligations
On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.
Verified fact — On 29 April 2026, the Italian Garante imposed a €8,600 fine for security failures (Arts. 5(1)(f) and 32 GDPR), including non‑compliant password storage. Takeaway — In Luxembourg, demonstrating proportional and state‑of‑the‑art security remains decisive.
The case
The Garante sanctioned a company for technical and organisational shortcomings, including storing credentials without state‑of‑the‑art protections and gaps in incident handling. Corrective powers relied on Arts. 58(2) and 83 GDPR, with reasoning based on proportionality, effectiveness and deterrence (provvedimento doc. web no. 10251777, 29/04/2026). In a separate decision dated 17/04/2026 (doc. web no. 10252460), the authority flagged a roughly two‑month delay in informing data subjects (Art. 34) and explicitly recalled the 2023 password storage guidelines (doc. 9962283).
Official Garante materials: 29/04/2026, doc. 10251777; 17/04/2026, doc. 10252460; “Conservazione delle Password” guidelines (07/12/2023).
Legal reasoning
- Text — Article 32 GDPR mandates appropriate technical and organisational measures, considering the state of the art, costs, processing context, and risks to rights and freedoms. Consolidated text: EUR‑Lex, Art. 32.
- Interpretation — The Garante ties shortcomings to Art. 5(1)(f) (integrity/confidentiality) and 32(1) (risk‑appropriate security). The 17/04/2026 decision also addresses Art. 34 (communication to data subjects) and refers to concrete password hashing standards (robust algorithms, salting, work factors) set out in the 2023 guidelines with Italy’s ACN.
- Fine methodology — The EDPB’s five‑step method (Guidelines 04/2022, v2.1 of 24/05/2023) weighs severity, duration, number of data subjects, negligence/intent, remedial measures, and financial capacity.
- Notification/communication — EDPB 01/2021 examples clarify risk levels, timelines and minimum content (Arts. 33/34). Luxembourg’s CNPD requires notification within 72 hours and communication to data subjects where risk is high.
What this means in Luxembourg (and cross‑border)
- High, evolving burden of proof — In CNPD audits you must show risk‑appropriate security: password policy documenting robust salted hashing, encryption at rest/in transit, secret management, logging, hardening, pentests, etc. A targeted cybersecurity audit helps evidence technical controls.
- Concrete state of the art — Decommission MD5/SHA‑1 and adopt suitable functions (Argon2, scrypt, bcrypt) with sufficient parameters, with implementation evidence, per the 2023 Garante/ACN guidelines.
- Incidents: timing and content — Notify the CNPD within 72 hours and inform data subjects where risk is high; credential exfiltration is a common scenario. Proactive dark web monitoring can help detect compromised credentials.
- Governance and traceability — Article 30 records should describe security measures “where possible” (cross‑ref Art. 32), plus retention policy, incident playbooks and audit evidence. For the Luxembourg legal framework, see GDPR obligations.
Practical examples
- Customer accounts (retail/banking/insurance) — Justify cryptographic choices for secrets, deploy phishing‑resistant MFA, segment environments, and evidence secret revocation/rotation.
- Internal SaaS (HR/payroll/time) — Harden authentication, log admin access, segment networks, and use DLP to prevent identifier list exfiltration.
- Cross‑border (BE/FR/DE) — Align to EU Art. 32 and consider country‑specific laws (e.g., Belgium CCTV rules).
Common audit pitfalls
- “Hashed” ≠ secure by default — Claiming hashed passwords without specifying function, salting and work factors.
- No evidence — Controls exist but no audit logs, tests, configurations or periodic reviews; Article 30 records lack general description of measures.
- Art. 33 vs Art. 34 confusion — Late notification to the CNPD or failure to inform data subjects when risk is high.
- Static “state of the art” — Legacy MD5/SHA‑1 hashes, stale keys, no upgrade plan.
- Uncontrolled processors — Vague clauses, no audit evidence, no restore testing; remember Art. 28 in tandem with Art. 32.
Official sources
- Garante — 29/04/2026 (doc. web no. 10251777)
- Garante — 17/04/2026 (doc. web no. 10252460)
- Garante & ACN — “Conservazione delle Password” (07/12/2023)
- EUR‑Lex — Regulation (EU) 2016/679, Article 32
- EDPB — Guidelines 01/2021 (breach notification)
- EDPB — Guidelines 04/2022 (fines)
- CNPD Luxembourg — Data breach notifications
- CNPD Luxembourg — Information security
- CNPD Luxembourg — GDPR Chapter IV
In short, even a €8,600 fine signals a clear trend: Article 32 is not symbolic; the CNPD expects up‑to‑date technical evidence, a response within 72 hours, and documentation linking risks, measures and demonstrable effectiveness.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →