A Fine Sized to the Failure, Not the Headline
On May 14, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, ordered telecom operator WINDTRE to pay €1,715,600 — a decision the regulator made public in its July 16 newsletter and that landed in international coverage around July 20 (Garante Privacy; Help Net Security). The case arose from two breaches WINDTRE itself reported in February 2025, in which attackers impersonated technical-support staff to convince employees at two retail locations to grant system access. From there, roughly 2 million enumeration requests against internal APIs exposed contact and account data belonging to more than 365,000 customers; for 41,359 of them, payment details — IBANs and partially masked card numbers with expiry dates — were also taken.
The Garante's findings were specific, not generic. Digital certificates and private keys were not stored in encrypted vaults or dedicated key-management systems, so a single compromised device could unlock broader access. Internal secondary APIs lacked the rate-limiting and CAPTCHA protections that OWASP has recommended as baseline practice for years — controls that, per the regulator's own reasoning, would likely have stopped the enumeration attack outright. WINDTRE argued its existing three-factor authentication, firewalls, and monitoring were adequate and blamed human error rather than technical design; the Garante rejected that framing and ordered the company to encrypt certificate storage and deploy mandatory password-management tooling going forward.
Steelmanning the Regulator
It is worth taking the Garante's position seriously before critiquing it. GDPR Article 5(1)(f) and Article 32 require "appropriate technical and organisational measures" against unauthorized access — and encrypted key storage plus rate-limiting on internal endpoints are not exotic asks. They are close to table stakes in any competent enterprise security program, doubly so for a telecom holding IBANs and card data for hundreds of thousands of subscribers. A social-engineering pretext succeeding against two retail employees is a people problem; two million enumeration requests going unthrottled against an internal API is an architecture problem, and architecture problems are exactly what Article 32 exists to police. Regulators who let "we got phished" excuse missing rate limits invite exactly the kind of low-effort intrusion WINDTRE suffered.
Why the Number Matters More Than the Ruling
Where this case earns its place as a model, though, is in how the Garante got to €1.7 million rather than a nine- or ten-figure number. The regulator explicitly weighed four mitigating factors: how quickly WINDTRE reported the breaches, the remediation it undertook afterward, its cooperation during the investigation, and the absence of prior violations on its record. That is proportionality applied in practice, not just invoked in a press release. For comparison, Ireland's Data Protection Commission has issued a cumulative €4.04 billion in fines since 2018 — including the €1.2 billion penalty against Meta in 2023 that remains the GDPR's largest single sanction — out of €7.1 billion in fines EU-wide, with roughly €1.2 billion issued in 2025 alone (DLA Piper GDPR Fines and Data Breach Survey, January 2026). Against that backdrop, a company that self-reported, fixed what broke, and cooperated fully was fined roughly a tenth of one percent of Meta's penalty for a breach of comparable scale in victim count. That gap should be read as the system working, not as under-enforcement — deterrence does not require every fine to be maximal, only that the penalty track culpability and conduct after the fact.
The Real Risk Is Stacking, Not Softness
The caution for policymakers isn't that this fine was too lenient — it's that WINDTRE's actual compliance burden won't stop at GDPR Article 32. The same infrastructure gaps that triggered this fine are also squarely within scope of the EU's NIS2 Directive for telecom operators, and the European Commission and Parliament agreed in May 2025 on a new GDPR Procedural Regulation aimed at streamlining cross-border enforcement cooperation among data protection authorities (European Commission, Data Protection in the EU). Separately, the European Data Protection Board opened public consultation in June 2026 on a common breach-notification template meant to standardize how incidents like WINDTRE's are reported across the bloc, with comments due August 5, 2026 (EDPB, Template for Personal Data Breach Notification). None of that is objectionable in isolation. But a telecom operator now faces overlapping GDPR, NIS2, and sector-specific cybersecurity obligations that each demand similar-but-not-identical evidence of "appropriate technical measures," audited by different bodies on different timelines. Harmonizing the reporting template is a small, sensible fix. Harmonizing the substantive security bar across GDPR and NIS2 — so operators build one control set rather than three overlapping ones — would do more for both compliance costs and actual security outcomes than either regime does alone.
The WINDTRE decision is a useful data point precisely because it's unremarkable: a real security failure, a fine proportionate to conduct and harm, and a clear remediation order. That's the enforcement EU tech policy should be optimizing for — more of it, applied consistently, rather than occasional blockbuster fines that generate headlines without a clear theory of proportionality behind the number.