A Phone Call, Not a Hack
On May 14, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, fined telecom operator Wind Tre €1,715,600 over two 2025 data breaches that exposed personal data belonging to more than 365,000 customers, including payment details — IBANs, partially masked card numbers, and expiry dates — for 41,359 of them (Garante newsletter n. 549). The breaches didn't start with a zero-day exploit. Attackers impersonating IT support technicians called staff at two Wind Tre retail stores and talked them into granting system access (Help Net Security).
From that initial foothold, weak engineering did the rest. The Garante's ruling (provvedimento n. 348/2026, doc. web 10263796) found that digital certificates and private keys weren't held in encrypted repositories or hardware security modules; point-of-sale credentials weren't managed through a password manager, leaving them effectively in plaintext despite three-factor authentication; and secondary internal APIs — unlike the primary ones — had never been through vulnerability testing or penetration testing, despite Wind Tre's own periodic OWASP-standard reviews (Garante provvedimento, doc. web 10263796). The Authority cited Article 5(1)(f) and Article 32(1)(b) of the GDPR — the integrity, confidentiality, and security-of-processing obligations — rather than any of the transparency or consent provisions that dominate most headline GDPR cases.
The Case for the Fine
The strongest argument for this fine doesn't rest on the social engineering itself — no company can make every employee immune to a convincing phone call. It rests on what happened after the call succeeded. GDPR Article 32 doesn't just require a firewall; it requires calibrating security measures to the sensitivity of what's being protected. A telecom carrier holding IBANs and card data for hundreds of thousands of customers is exactly the kind of processor for whom encrypted key storage and tested internal APIs are baseline, not aspirational. Wind Tre had the primary APIs tested and left the secondary ones exposed — a gap that's about resourcing and process discipline, not sophistication of the attacker. On that reading, the Garante isn't punishing Wind Tre for being targeted; it's punishing a company for the entirely foreseeable and preventable technical debt that turned a social-engineering call into a 365,000-record breach.
Where the Proportionality Argument Lands
What makes this ruling notable isn't the size of the fine — it's how small the Garante kept it relative to what it could have imposed. €1,715,600 represents roughly 1% of the €171.56 million statutory ceiling available to the Authority, itself calculated as 4% of Wind Tre's global annual turnover under GDPR Article 83(5) (Garante provvedimento, doc. web 10263796). The Garante explicitly credited Wind Tre's prompt breach notification, the remedial measures it implemented afterward, its cooperation with the investigation, and the absence of prior privacy violations (Help Net Security).
That's the enforcement design worth defending. A regulator that maxes out fines regardless of a company's post-breach conduct teaches every general counsel in Europe the same lesson: delay disclosure, litigate everything, and treat the regulator as an adversary rather than a party you cooperate with. A regulator that visibly discounts the penalty for fast notification and good-faith remediation — as the Garante did here — creates the opposite incentive, which is the one GDPR's 72-hour breach-notification rule was actually designed to reward. Against a European enforcement backdrop where the CMS GDPR Enforcement Tracker records roughly €6.11 billion in fines across 2,685 documented cases since 2018, with telecom and broadcasting among the top three sectors by average fine size (CMS Enforcement Tracker Report 2025/2026), a precisely scoped, cooperation-rewarding penalty is the more defensible model — not a weaker one.
The Overlap Regulators Should Resolve
The one caution: this ruling functions less like a privacy decision and more like a cybersecurity audit report, with the Garante specifying exactly which controls — HSM-backed key storage, password managers, API penetration testing — a telecom operator must run. Telecoms operating in the EU are also "essential entities" under the NIS2 Directive, which imposes its own risk-management and incident-reporting obligations enforced by separate national cybersecurity authorities. When a data protection authority starts issuing what amounts to a technical cybersecurity code under Article 32, alongside a parallel NIS2 regime covering the same infrastructure, companies risk facing two regulators auditing the same certificate-management practices under different legal bases and timelines. Member states and the EDPB should be working now to align GDPR security enforcement with NIS2 competent authorities, so telecoms get one coherent standard to build toward rather than two overlapping ones to defend against.
Bottom Line
The Wind Tre fine is a good template: specific, evidence-based technical findings; a penalty calibrated to actual culpability and cooperation rather than maximum deterrence theater. Regulators looking to make GDPR enforcement more credible — and less of a blunt instrument — should study this ruling's proportionality, not just its price tag.