← All articles

consultant

GDPR Article 32: a small Italian fine, big obligations

On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.

Verified fact — On 29 April 2026, the Italian Garante imposed a €8,600 fine for security failures (Arts. 5(1)(f) and 32 GDPR), including non‑compliant password storage. Takeaway — In Luxembourg, demonstrating proportional and state‑of‑the‑art security remains decisive.

The case

The Garante sanctioned a company for technical and organisational shortcomings, including storing credentials without state‑of‑the‑art protections and gaps in incident handling. Corrective powers relied on Arts. 58(2) and 83 GDPR, with reasoning based on proportionality, effectiveness and deterrence (provvedimento doc. web no. 10251777, 29/04/2026). In a separate decision dated 17/04/2026 (doc. web no. 10252460), the authority flagged a roughly two‑month delay in informing data subjects (Art. 34) and explicitly recalled the 2023 password storage guidelines (doc. 9962283).

Official Garante materials: 29/04/2026, doc. 10251777; 17/04/2026, doc. 10252460; “Conservazione delle Password” guidelines (07/12/2023).

Legal reasoning

  • Text — Article 32 GDPR mandates appropriate technical and organisational measures, considering the state of the art, costs, processing context, and risks to rights and freedoms. Consolidated text: EUR‑Lex, Art. 32.
  • Interpretation — The Garante ties shortcomings to Art. 5(1)(f) (integrity/confidentiality) and 32(1) (risk‑appropriate security). The 17/04/2026 decision also addresses Art. 34 (communication to data subjects) and refers to concrete password hashing standards (robust algorithms, salting, work factors) set out in the 2023 guidelines with Italy’s ACN.
  • Fine methodology — The EDPB’s five‑step method (Guidelines 04/2022, v2.1 of 24/05/2023) weighs severity, duration, number of data subjects, negligence/intent, remedial measures, and financial capacity.
  • Notification/communicationEDPB 01/2021 examples clarify risk levels, timelines and minimum content (Arts. 33/34). Luxembourg’s CNPD requires notification within 72 hours and communication to data subjects where risk is high.

What this means in Luxembourg (and cross‑border)

  • High, evolving burden of proof — In CNPD audits you must show risk‑appropriate security: password policy documenting robust salted hashing, encryption at rest/in transit, secret management, logging, hardening, pentests, etc. A targeted cybersecurity audit helps evidence technical controls.
  • Concrete state of the art — Decommission MD5/SHA‑1 and adopt suitable functions (Argon2, scrypt, bcrypt) with sufficient parameters, with implementation evidence, per the 2023 Garante/ACN guidelines.
  • Incidents: timing and content — Notify the CNPD within 72 hours and inform data subjects where risk is high; credential exfiltration is a common scenario. Proactive dark web monitoring can help detect compromised credentials.
  • Governance and traceability — Article 30 records should describe security measures “where possible” (cross‑ref Art. 32), plus retention policy, incident playbooks and audit evidence. For the Luxembourg legal framework, see GDPR obligations.

Practical examples

  • Customer accounts (retail/banking/insurance) — Justify cryptographic choices for secrets, deploy phishing‑resistant MFA, segment environments, and evidence secret revocation/rotation.
  • Internal SaaS (HR/payroll/time) — Harden authentication, log admin access, segment networks, and use DLP to prevent identifier list exfiltration.
  • Cross‑border (BE/FR/DE) — Align to EU Art. 32 and consider country‑specific laws (e.g., Belgium CCTV rules).

Common audit pitfalls

  1. “Hashed” ≠ secure by default — Claiming hashed passwords without specifying function, salting and work factors.
  2. No evidence — Controls exist but no audit logs, tests, configurations or periodic reviews; Article 30 records lack general description of measures.
  3. Art. 33 vs Art. 34 confusion — Late notification to the CNPD or failure to inform data subjects when risk is high.
  4. Static “state of the art” — Legacy MD5/SHA‑1 hashes, stale keys, no upgrade plan.
  5. Uncontrolled processors — Vague clauses, no audit evidence, no restore testing; remember Art. 28 in tandem with Art. 32.

Official sources

In short, even a €8,600 fine signals a clear trend: Article 32 is not symbolic; the CNPD expects up‑to‑date technical evidence, a response within 72 hours, and documentation linking risks, measures and demonstrable effectiveness.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →