According to the Privacy Guarantor, the bank must notify within 20 days the customers whose accounts have been checked by the employee of the Bisceglie branch who has made over 6,600 accesses in two years. The Bari prosecutor’s office is investigating the case.
The final figure exceeds quota 6,600. According to initial investigations, these are the accesses made within two years by Vincenzo Coviello, the employee fired from the bank on charges of having illegitimately controlled the accounts of variously famous people. A mass of information on which the President has now decided to intervene Privacy Guarantor requiring Intesa Sanpaolo to notify all people involved in this matter.
At the moment the reasons that led Coviello to this are not clear access such a large number of accounts. It is unclear whether it was just voyeurism, whether that information was passed on to third parties or whether he himself had another plan to move around the bank. 6,600 accesses, it seems in two years, are equivalent to about ten accesses a day.
There are many famous names involved, from politicians to footballers. There are Giorgia Meloni, Guido Crosetto And Daniela Santanchè. But also Francesco Tottithe account of Juventus, Al Bano And Paolo Bonolis. At the moment the names have emerged from the investigations of the Bari Prosecutor’s Office, the suspect worked in the Bisceglie branch. Now, however, with the Guarantor’s decision, the people whose accounts were checked will be informed of the access.
The statement from the Privacy Guarantor
The deadline given by the Privacy Guarantor to Intesa Sanpaolo is 20 days: “Intesa Sanpaolo Spa has 20 days to inform customers involved in the violation of their personal and banking data, which occurred through undue access carried out by an employee of the Bank”.
Interesting to note that in this case the Guarantor he denied the bank’s positions: “In fact, the Authority believes, differently from what was assessed by the Bank, that the violation of personal data presents a high risk for the rights and freedoms of the people involved, taking into account the nature of the violation, the categories of data processed, the seriousness and the consequences that could arise from it.”
Intesa Sanpaolo’s position: “There is no evidence of data transfer”
Intesa Sanpaolo commented in a note on provision of the Guarantor: “The bank has already introduced further control systems and processes and ensures maximum collaboration with the competent authorities, in the belief that, also thanks to this collaboration, the security level can further improve. In the meantime, Intesa Sanpaolo was able to carry out further checks and analyzes regarding the access to customer data carried out by the employee, who was later fired, from which it emerges that the number of customers affected by anomalous access is significantly lower compared to the number published so far by the press. Furthermore, it had already been verified and is still confirmed that there is no evidence of data transfer outside the Bank, and in particular of communications to third parties, nor of an anomaly in the IT system, which was not impacted”.

