[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTdop7c1MYkuGHJW0P2Ie32Ohoa9Ek7ZD2QrswTuVhto":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"7842cdfb-b5cd-490d-8649-5aa7becdb54a","IP (Slovenia) - 0609-113\u002F2025\u002F9","ip-slovenia-0609-113-2025-9-566124","← Older revision Revision as of 13:33, 1 September 2026 Line 84: Line 84: }} }} The DPA fined a company €5,320 for a failure to implement appropriate technical and organisational measures in connection with the destruction of employees' personal data. The DPA fined a company €5,320 for a failure to implement appropriate technical and organisational measures in connection with the destruction of employees' personal data contained in paper documents. Discarded documents were left unsecured and accessible to anyone. == English Summary == == English Summary ==","Slovenia's Information Commissioner (IP) has fined a company €5,320 for failing to implement adequate technical and organizational measures to protect employee personal data. Discarded paper documents containing sensitive information like names, insurance numbers, and addresses were left unsecured and accessible to unauthorized individuals. This violation breaches Articles 32 and 5(1)(f) of the GDPR, emphasizing the need for robust data destruction and confidentiality protocols.","Slovenian DPA fines company €5,320 for unsecured employee personal data.","Help IP (Slovenia) - 0609-113\u002F2025\u002F9: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:00, 31 August 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators155 editsTag: Visual edit← Older edit Latest revision as of 13:33, 1 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators155 editsTag: Visual edit Line 84: Line 84: }}}} The DPA fined a company €5,320 for a failure to implement appropriate technical and organisational measures in connection with the destruction of employees' personal data.The DPA fined a company €5,320 for a failure to implement appropriate technical and organisational measures in connection with the destruction of employees' personal data contained in paper documents. Discarded documents were left unsecured and accessible to anyone. == English Summary ==== English Summary == Latest revision as of 13:33, 1 September 2026 IP - 0609-113\u002F2025\u002F9 Authority: IP (Slovenia) Jurisdiction: Slovenia Relevant Law: Article 5(1)(f) GDPR Article 32 GDPR Type: Investigation Outcome: n\u002Fa Started: Decided: Published: 27.07.2026 Fine: 5320.0 EUR Parties: n\u002Fa National Case Number\u002FName: 0609-113\u002F2025\u002F9 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Slovenian Original Source: IP (in SL) Initial Contributor: av The DPA fined a company €5,320 for a failure to implement appropriate technical and organisational measures in connection with the destruction of employees' personal data contained in paper documents. Discarded documents were left unsecured and accessible to anyone. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents included the first name, last name, insurance number, date of birth, residential address, and gender of the data subjects. The discarded paper documents were left completely unsecured and accessible to anyone. Holding The DPA issued the controller a fine of €5,320 for infringements of Articles 32 and 5(1)(f) GDPR. The DPA held that the controller had failed to implement appropriate technical and organisational measures required by Article 32 GDPR to ensure an adequate level of security in the processing of employees’ personal data. According to the DPA, such measures would have prevented unauthorised disclosure of and access to personal data. Furthermore, the DPA held that the controller had also violated the principles of integrity and confidentiality set forth in Article 5(1)(f) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Slovenian original. Please refer to the Slovenian original for more details. Number: 0609-113\u002F2025\u002F9 Date: … The Information Commissioner (hereinafter: the administrative authority) issues this decision through the authorized official …, the State Supervisor for Personal Data Protection, in the performance of her official duties pursuant to the second paragraph of Article 51 and Article 46 of the Minor Offenses Act (Official Gazette of the Republic of Slovenia, No. 29\u002F11—official consolidated text, 21\u002F13, 111\u002F13, 74\u002F14—Constitutional Court Decision, 92\u002F14—Constitutional Court Decision, 32\u002F16, 15\u002F17—Constitutional Court Decision, 73\u002F19—Constitutional Court Decision, 175\u002F20—ZIUOPDVE, 5\u002F21—Constitutional Court Decision, 38\u002F24, 100\u002F25 – ZS-1, and 10\u002F26; hereinafter: ZP-1), Articles 2 and 8 of the Information Commissioner Act (Official Gazette of the Republic of Slovenia, Nos. 113\u002F05 and 51\u002F07 – ZUstS-A, hereinafter: ZInfP), in the administrative proceeding against the legal entity …, registration number: …. (hereinafter: …), for an administrative offense under the first paragraph of Article 95 of the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163\u002F22, 40\u002F25 – ZInfV-1 and 10\u002F26 – ZP-1L; hereinafter ZVOP-2) in conjunction with subparagraph (a) of the fifth paragraph of Article 83 of Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter: the General Regulation), the following DECISION ON AN ADMINISTRATIVE OFFENSE The offender, the responsible legal entity: …, registration number: …, is liable for an administrative offense under the first paragraph of Article 95 of ZVOP-2 in conjunction with point (a) of the fifth paragraph of Article 83 of the General Regulation committed on … by …, in that, as the responsible person of the legal entity …, when destroying the personal data of individuals employed by the legal entity, which were contained in paper documents, failed to ensure the appropriate security of such processing, as he failed to ensure the implementation of appropriate organizational measures in accordance with the provisions of Article 32 of the General Data Protection Regulation, which would have prevented unauthorized disclosure of and access to personal data; as a result, on the date the violation was committed, the document …, which contained the personal data of the employee … (first name, last name, insurance number, date of birth, residential address, employer information, gender), including his or her personal health data (…), and the document …, which contained the personal data of the employee … (first name, last name, employer’s name, date …), were found among the discarded documentation of the legal entity, which was completely unsecured and accessible to anyone, having been discarded … at the location between …, from … onward, …, thereby violating the fundamental principle of integrity and confidentiality regarding the processing of personal data, as set forth in point (f) of the first paragraph of Article 5 of the General Data Protection Regulation, since, in the aforementioned processing (destruction) of personal data, he failed to implement appropriate technical and organizational measures to ensure an adequate level of security in the processing of employees’ personal data at the legal entity. … committed the above-alleged violation through his act (omission) in the course of business and on behalf of and using the resources of the legal entity …, at which he was authorized to perform work at the time the violation was committed …, as a result of which the legal entity … is liable for the aforementioned violation as the responsible legal entity in accordance with the first paragraph of Article 14 of ZP-1. The violators of the liable legal entity are therefore liable, pursuant to the first paragraph of Article 95 of ZVOP-2 in conjunction with point (a) of the fifth paragraph of Article 83 of the General Regulation and by application of the third paragraph of Article 52 of the ZP-1, Article 115 of the ZVOP-2, the first and second paragraphs of Article 83 of the General Regulation, and the second paragraph of Article 26 of the ZP-1 for the administrative offense a f i n e A FINE in the amount of 5,320 EUR. The offender, the responsible legal entity …, must pay the fine in the amount of 5,320 euros to the following account: Information Commissioner, Recipient’s IBAN: SI56 0110 0845 0051 825, Recipient’s bank BIC code: BSLJSI2X, purpose code: GOVT, payment purpose: 0609-113\u002F2025\u002F9 fine, reference: SI11 12157-7120010- 202662. The offender, the responsible legal entity … must, pursuant to the first paragraph of Article 143 in conjunction with the first paragraph of Article 144 and the second paragraph of Article 58 ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=IP_(Slovenia)_-_0609-113\u002F2025\u002F9&diff=52863&oldid=52840","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F7\u002F78\u002FLogoSI.png","2026-09-01T13:33:48+00:00","2026-09-01T14:00:19.416476+00:00",7,[18],{"name":19,"type":20},"IP (Slovenia)","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]