• via Alberto da Giussano, 26, 20145 Milano
  • +39 02 8295 4969
  • info@studiolegalebianucci.it
Avv. Marco Bianucci
Avv. Marco Bianucci

Criminal Lawyer

When you suspect that a bank has used, consulted, or communicated your personal data without a legitimate reason, the first question is often very concrete: what can I request, and what consequences can the incident have? I will explain how to distinguish an unjustified internal access, a disclosure to third parties, a data error, and a true security breach. These situations are close only in appearance: the rights you can exercise, the content of the response you can demand, and any claim for damages change.

I also want to clarify a frequent misunderstanding. Incorrect data use is not automatically misappropriation. Privacy protection, civil liability, and any criminal relevance have different prerequisites. Understanding this difference helps choose a proportionate step, without underestimating the incident or attributing a qualification to it that the facts do not support.

When the Use of Bank Data Becomes Unlawful

The bank may process data only for specified purposes and on an appropriate legal basis. The execution of an account, a loan, or a payment necessarily requires some processing; other operations may depend on legal obligations, fraud prevention, or specific contractual needs. Consent, therefore, is not the only possible basis for processing. However, this does not allow indiscriminate use of the information available in banking systems.

The European regulation requires that data be processed lawfully, fairly, and transparently, and that it be collected and used for explicit and legitimate purposes. It also requires the controller to be able to demonstrate compliance with these principles. You can consult the principles and conditions of lawfulness in Articles 5 and 6 of Regulation (EU) 2016/679.

Not every consultation by an employee is lawful just because it happens from inside the bank. An employee may have technical access credentials, but they must use the data within the limits of their duties and the instructions received. Consulting an acquaintance's account out of curiosity, searching for information unnecessary to the assigned file, or using customer contact details for a purpose unrelated to the relationship may indicate non-compliant processing.

Data Access, Information, and Response Times

The right of access serves first of all to understand what data the bank is processing and why. You can request confirmation of whether processing is taking place, a copy of the personal data, and information on the purposes, categories of data, recipients or categories of recipients, retention period, and the origin of the data when you did not provide them. This is the essential content of Article 15 of the GDPR.

A well-formulated request should not turn into a generic accusation. It is useful to indicate the episode that raised the doubt, the period concerned, and what you want to clarify: for example, a communication received from third parties, an inaccurate datum appearing in a file, unwanted commercial contacts, or the suspicion of access extraneous to a service necessity. Precision helps obtain a verifiable response.

The controller must provide information without undue delay and, as a rule, within one month of the request. The term may be extended by another two months only if complexity and the number of requests make it necessary; however, the bank must inform the data subject of the extension and the reasons within the first month. If it does not intend to follow up on the request, it must explain the refusal and indicate the possibility of lodging a complaint or seeking a judicial remedy. These rules are provided by Article 12 of the GDPR.

Data Breach and Notification to the Customer

A personal data breach does not coincide with every banking malfunction. A breach occurs when there is accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed. It can depend on human error, stolen credentials, sending to the wrong recipient, a system deficiency, or unauthorized internal behavior.

The bank is not required to communicate every technical or organizational incident to the customer. Article 33 of the GDPR requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The 72-hour deadline concerns the bank and the authority, not a deadline imposed on you.

Direct communication to the data subject is instead required when the breach is likely to result in a high risk to their rights and freedoms. It must describe the incident in clear language and indicate the contact point, possible consequences, and measures adopted. In some cases, individual communication is not mandatory, for example if data rendered unintelligible to any unauthorized person has been used, or if measures ensuring that the high risk is no longer likely to materialize have been taken. The distinction is governed by Articles 33 and 34 of the GDPR.

Rectification, Restriction, Objection, and Complaint

The most useful remedy depends on what is happening to the data. If information is wrong, you can request rectification. If you contest the accuracy or consider the use unlawful but need to keep the data to assert a right, you can request the restriction of processing: the bank retains the data but cannot normally use it beyond the limits established by law. Erasure is not always feasible because bank data and documents may need to be kept for regulatory obligations or to defend a right.

If the bank uses your data for direct marketing, you can object to that processing at any time. After the objection, the data must no longer be processed for such purpose. For other processing based on public interest or legitimate interest, objection requires reasons relating to your situation and can only be overridden by compelling legitimate grounds of the bank or the establishment, exercise, or defense of legal claims. The discipline is found in Articles 18 and 21 of Regulation (EU) 2016/679.

A complaint to the Guarantor does not necessarily replace a judicial action. The GDPR recognizes the right to lodge a complaint with a supervisory authority if you consider that the processing violates privacy rules, and separately, the right to an effective judicial remedy against a controller or processor. The two paths can have different functions: the complaint aims at compliance monitoring and authority measures; judicial action can also serve to assert individual claims, including damages. See Articles 77 and 79 of the GDPR.

Damages: Violation Alone Is Not Enough

To obtain damages, a violation, damage, and a link between the two are required. Article 82 of the GDPR recognizes the right to compensation for material or non-material damage caused by a violation of the regulation. Material damage may concern a concrete financial loss; non-material damage may concern effectively suffered non-pecuniary consequences, such as prejudice to one's personal sphere. It is not sufficient to indicate in the abstract that a rule has been violated.

The decisive fact is not only the apparent gravity of the incident. What counts, among other things, is the type of information involved, who received or consulted it, how long it remained exposed, whether the use had consequences in private life or economic relations, and what measures were adopted to remedy it. An incorrect communication blocked immediately and a wide disclosure produce different problems.

The bank is liable for the damage caused by its processing which infringes the GDPR; the processor is liable in the cases provided for by the same norm. An exemption is provided when the subject proves that the damaging event is not in any way attributable to them. The rule and joint and several liability in the presence of multiple involved subjects are contained in Article 82 of the GDPR. For this reason, the claim for damages must be distinguished from the simple request for clarifications, correction, or cessation of processing.

Privacy, Civil Liability, and Offences: Why They Are Not the Same Thing

Unlawful data access does not turn data into stolen money or goods. Misappropriation under Article 646 of the criminal code concerns the misappropriation, in order to procure an unjust profit for oneself or others, of money or movable property belonging to others of which one has possession. For this reason, the mere consultation or undue dissemination of banking information does not coincide, in itself, with such an offense. The text of the article can be found in the Criminal Code published on Normattiva.

This does not mean that conduct regarding data is irrelevant. It can entail a violation of GDPR, tort liability, and, when all elements established by law are met, also a possible different criminal relevance. Article 167 of the Personal Data Protection Code provides for specific hypotheses of unlawful processing, with further conditions that include, depending on the case, particular violations, the purpose of profit or harm, and harm to the data subject. Criminal qualification requires precise facts, not a formula used to describe the distress suffered.

The national framework integrates with the European regulation: Article 1 of the Privacy Code expressly recalls processing according to GDPR and in compliance with dignity, rights, and fundamental freedoms. For the text of the Code and the recalled criminal provisions, you can see Legislative Decree No. 196 of 2003 on Normattiva. If unauthorized account operations also emerge, the problem of data use must be kept separate from the contestation of financial operations, which has its own prerequisites and remedies.

How to Formulate a Request Without Confusing Issues

Preserve the facts before evaluations. Bank communications, emails, messages, screenshots, bank statements, the date of the incident, and names of any recipients involved help delimit the affair. It is not necessary to already have complete proof of internal access to ask for clarifications, but it is important not to state as certain what is still only a suspicion.

A first request can ask what data was processed, for what purposes, whether there were external recipients, and what measures were adopted in relation to the specific incident. If the problem is inaccurate data, rectification is more consistent than a request for erasure; if you fear further use during a dispute, restriction may be more suitable. The remedy must be chosen based on the effect you want to obtain. If the fact has already produced concrete damage or the bank's response leaves essential points open, you can contact me to evaluate the most suitable protection.

Frequently Asked Questions

Can I know who consulted my data at the bank?

You can ask for information on the processing and recipients of the data. The right of access does not automatically guarantee the delivery of every technical log or the name of each operator. However, if you report a circumscribed episode, the bank must handle the request transparently and provide the feedback required by GDPR, explaining any concrete limits.

Must the bank always notify me if it loses or exposes my data?

No, notice to the customer depends on high risk. The bank must evaluate the episode and, when the breach presents a high risk to the rights and freedoms of individuals, communicate it without undue delay. The absence of communication does not prove in itself that nothing happened, nor does it automatically demonstrate a violation.

To claim damages, must I prove economic loss?

No, the damage can also be non-material. To obtain compensation, however, a mere privacy violation is not enough: it is necessary to allege and prove effective prejudice and the link with the unlawful act. To request access, rectification, objection, restriction, or file a complaint, it is instead not necessary to prove economic loss.

Can I request the erasure of all data after closing the account?

Not always, because some data may need to be retained. Closing the relationship does not automatically erase legal obligations, documentation needs, or the possibility of defending rights. You can still ask to know retention times and criteria, object to marketing, and request the erasure of data for which a legitimate basis no longer exists.

Is unlawful access to account data misappropriation?

As a rule no, not for the mere fact of access. Misappropriation concerns money or movable property belonging to others of which a person has possession and which they appropriate for an unjust profit. Improper use of data can have privacy, civil, or, under specific circumstances, criminal relevance, but requires a qualification based on concrete facts.