Back to Feed
PolicyAug 11, 2026

IP (Slovenia) - 0609-41/2026/7

Slovenian DPA fines company €1,282 for failing to conclude a data processing agreement.

Summary

The Slovenian Information Protection Agency (IP) fined a company €1,282 for violating Article 28(3) of the GDPR. The company failed to establish a valid data processing agreement with its service provider, who handled personal data, managed databases, and provided technical support for the controller's employees. The IP held the company liable as the responsible legal entity for its representative's failure to properly regulate the contractual relationship with the processor.

Full text

Help IP (Slovenia) - 0609-41/2026/7: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 07:25, 11 August 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators126 edits Tag: Decisions [1.0] Latest revision as of 17:42, 11 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators118 editsTag: Visual edit Line 80: Line 80: }}}} The DPA fined the company €1,282 for a failure to conclude a data processing agreement required under [[Article 28 GDPR|Article 28(3) GDPR]] with its processor. The DPA fined a company €1,282 for a failure to conclude a data processing agreement required under [[Article 28 GDPR|Article 28(3) GDPR]] with its processor. == English Summary ==== English Summary == === Facts ====== Facts === A company (the controller) used another service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. The processor processed the personal data of the controller's employees in the performance of its duties. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor and regulating the processing operations entrusted to it.A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. The processor processed the personal data of the controller's employees in the performance of its duties. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it. === Holding ====== Holding === The DPA held that the controller had violated [[Article 28 GDPR|Article 28(3) GDPR]] and issued the controller a fine of €1,282. It concluded that the legal representative of the controller had failed to properly regulate the contractual relationship with the processor: the processing operations carried out by the processor were not governed by a contract or other legal act in accordance with EU or Member State law, setting out the obligations of the processor. As the representative acted in the performance of their duties as an employee and on behalf of the controller, the DPA held that the controller was liable for the offense as the responsible legal entity.The DPA held that the controller had violated [[Article 28 GDPR|Article 28(3) GDPR]] and issued the controller a fine of €1,282. It concluded that the legal representative of the controller had failed to properly conclude the contractual relationship with the processor: the processing operations carried out by the processor were not governed by a contract or other legal act in accordance with EU or Member State law, setting out the obligations of the processor. As the representative acted in the performance of their duties as an employee and on behalf of the controller, the DPA held that the controller was liable for the infringement as the responsible legal entity. == Comment ==== Comment == Latest revision as of 17:42, 11 August 2026 IP - 0609-41/2026/7 Authority: IP (Slovenia) Jurisdiction: Slovenia Relevant Law: Article 28(3) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 22.07.2026 Fine: 1282.0 EUR Parties: n/a National Case Number/Name: 0609-41/2026/7 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Slovenian Original Source: Praksa IP (in SL) Initial Contributor: av The DPA fined a company €1,282 for a failure to conclude a data processing agreement required under Article 28(3) GDPR with its processor. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. The processor processed the personal data of the controller's employees in the performance of its duties. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it. Holding The DPA held that the controller had violated Article 28(3) GDPR and issued the controller a fine of €1,282. It concluded that the legal representative of the controller had failed to properly conclude the contractual relationship with the processor: the processing operations carried out by the processor were not governed by a contract or other legal act in accordance with EU or Member State law, setting out the obligations of the processor. As the representative acted in the performance of their duties as an employee and on behalf of the controller, the DPA held that the controller was liable for the infringement as the responsible legal entity. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Slovenian original. Please refer to the Slovenian original for more details. 1 Number: 0609-41/2026/7 Date: … The Information Commissioner (hereinafter: the administrative authority), through the authorized official …, acting in an official capacity, hereby issues, pursuant to the second paragraph of Article 51 and Article 46 of the Minor Offenses Act (Official Gazette of the Republic of Slovenia, No. 29/11—consolidated text, 21/13, 111/13, 74/14 – Constitutional Court Decision, 92/14 – Constitutional Court Decision, 32/16, 15/17 – Constitutional Court Decision, 73/19 – Constitutional Court Decision, 175/20 – ZIUOPDVE, 5/21 – Constitutional Court Decision, 38/24, 100/25 – ZS-1 and 10/26; hereinafter: ZP-1) and Articles 2 and 8 of the Information Commissioner Act (Official Gazette of the Republic of Slovenia, Nos. 113/05 and 51/07 – ZUstS-A) in the proceedings concerning an administrative offense committed by the legal entity …, for an offense under the first paragraph of Article 95 of the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163/22, 40/25 – ZInfV-1 and 10/26 – ZP-1L, hereinafter: ZVOP-2) in conjunction with point (a) of the fourth paragraph of Article 83 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: the General Regulation), the following DECISION ON AN ADMINISTRATIVE OFFENSE The offending legal entity: …, is liable for an administrative offense under the first paragraph of Article 95 of ZVOP-2 in conjunction with point (a) of the fourth paragraph of Article 83 of the General Regulation, which was committed in the period from … to … in … by …, in that, as the legal representative of the legal entity—in which he served as its …—he was obligated to ensure that the legal entity operated in accordance with the General Regulation, the ZVOP-2, and the legal entity’s internal regulations, failed to properly regulate the contractual relationship with the personal data processor, the company …, which provided the service … to the legal entity …, under which, for the purpose of storing personal data, managing the database, and providing technical support and maintenance on behalf of and for the account of the legal entity …, it processed the personal data of employees of the leg

Entities

Information Protection Agency (vendor)