[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fh5Jzww1l26uf16c7UZZAvyRLQeDs3vHnc1jFnDI0dFo":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"06b7ff34-ece5-4d84-84a8-7c2774661dd5","IP (Slovenia) - 0609-41\u002F2026\u002F7","ip-slovenia-0609-41-2026-7-a3f4a5","← Older revision Revision as of 07:31, 12 August 2026 (One intermediate revision by the same user not shown) Line 12: Line 12: |Original_Source_Name_1=Praksa IP |Original_Source_Name_1=Praksa IP |Original_Source_Link_1=https:\u002F\u002Fwww.ip-rs.si\u002Fgo?u=%2Ffileadmin%2Fuser_upload%2Fzip%2FPonovna_uporaba%2F2026%2FJunij%2Fjunij-2026-zp-odlocbe.zip |Original_Source_Link_1=https:\u002F\u002Fwww.ip-rs.si\u002Fgo?u=%2Ffileadmin%2Fuser_upload%2Fzip%2FPonovna_uporaba%2F2026%2FJunij%2F0609-41-2026-7.docx |Original_Source_Language_1=Slovenian |Original_Source_Language_1=Slovenian |Original_Source_Language__Code_1=SL |Original_Source_Language__Code_1=SL Line 85: Line 85: === Facts === === Facts === A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. The processor processed the personal data of the controller's employees in the performance of its duties. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it. A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it.","Slovenia's Information Protection Authority (IP) has fined a company €1,282 for violating GDPR Article 28(3). The company, acting as a data controller, failed to establish a valid data processing agreement with its service provider, which managed employee personal data. The IP found that the controller's legal representative neglected to properly formalize the contractual relationship, leading to the fine.","Slovenian DPA fines company €1,282 for failing to sign a data processing agreement.","Help IP (Slovenia) - 0609-41\u002F2026\u002F7: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 17:42, 11 August 2026 view sourceFm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators118 editsTag: Visual edit← Older edit Latest revision as of 07:31, 12 August 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators130 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 12: Line 12: |Original_Source_Name_1=Praksa IP|Original_Source_Name_1=Praksa IP |Original_Source_Link_1=https:\u002F\u002Fwww.ip-rs.si\u002Fgo?u=%2Ffileadmin%2Fuser_upload%2Fzip%2FPonovna_uporaba%2F2026%2FJunij%2Fjunij-2026-zp-odlocbe.zip|Original_Source_Link_1=https:\u002F\u002Fwww.ip-rs.si\u002Fgo?u=%2Ffileadmin%2Fuser_upload%2Fzip%2FPonovna_uporaba%2F2026%2FJunij%2F0609-41-2026-7.docx |Original_Source_Language_1=Slovenian|Original_Source_Language_1=Slovenian |Original_Source_Language__Code_1=SL|Original_Source_Language__Code_1=SL Line 85: Line 85: === Facts ====== Facts === A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. The processor processed the personal data of the controller's employees in the performance of its duties. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it.A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it. Latest revision as of 07:31, 12 August 2026 IP - 0609-41\u002F2026\u002F7 Authority: IP (Slovenia) Jurisdiction: Slovenia Relevant Law: Article 28(3) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 22.07.2026 Fine: 1282.0 EUR Parties: n\u002Fa National Case Number\u002FName: 0609-41\u002F2026\u002F7 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Slovenian Original Source: Praksa IP (in SL) Initial Contributor: av The DPA fined a company €1,282 for a failure to conclude a data processing agreement required under Article 28(3) GDPR with its processor. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal representative of the controller, who was responsible for ensuring that the controller complied with the GDPR, had not concluded a valid contract defining the contractual relationship with the processor, regulating the processing operations entrusted to it. Holding The DPA held that the controller had violated Article 28(3) GDPR and issued the controller a fine of €1,282. It concluded that the legal representative of the controller had failed to properly conclude the contractual relationship with the processor: the processing operations carried out by the processor were not governed by a contract or other legal act in accordance with EU or Member State law, setting out the obligations of the processor. As the representative acted in the performance of their duties as an employee and on behalf of the controller, the DPA held that the controller was liable for the infringement as the responsible legal entity. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Slovenian original. Please refer to the Slovenian original for more details. 1 Number: 0609-41\u002F2026\u002F7 Date: … The Information Commissioner (hereinafter: the administrative authority), through the authorized official …, acting in an official capacity, hereby issues, pursuant to the second paragraph of Article 51 and Article 46 of the Minor Offenses Act (Official Gazette of the Republic of Slovenia, No. 29\u002F11—consolidated text, 21\u002F13, 111\u002F13, 74\u002F14 – Constitutional Court Decision, 92\u002F14 – Constitutional Court Decision, 32\u002F16, 15\u002F17 – Constitutional Court Decision, 73\u002F19 – Constitutional Court Decision, 175\u002F20 – ZIUOPDVE, 5\u002F21 – Constitutional Court Decision, 38\u002F24, 100\u002F25 – ZS-1 and 10\u002F26; hereinafter: ZP-1) and Articles 2 and 8 of the Information Commissioner Act (Official Gazette of the Republic of Slovenia, Nos. 113\u002F05 and 51\u002F07 – ZUstS-A) in the proceedings concerning an administrative offense committed by the legal entity …, for an offense under the first paragraph of Article 95 of the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163\u002F22, 40\u002F25 – ZInfV-1 and 10\u002F26 – ZP-1L, hereinafter: ZVOP-2) in conjunction with point (a) of the fourth paragraph of Article 83 of Regulation (EU) 2016\u002F679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\u002F46\u002FEC (General Data Protection Regulation, hereinafter: the General Regulation), the following DECISION ON AN ADMINISTRATIVE OFFENSE The offending legal entity: …, is liable for an administrative offense under the first paragraph of Article 95 of ZVOP-2 in conjunction with point (a) of the fourth paragraph of Article 83 of the General Regulation, which was committed in the period from … to … in … by …, in that, as the legal representative of the legal entity—in which he served as its …—he was obligated to ensure that the legal entity operated in accordance with the General Regulation, the ZVOP-2, and the legal entity’s internal regulations, failed to properly regulate the contractual relationship with the personal data processor, the company …, which provided the service … to the legal entity …, under which, for the purpose of storing personal data, managing the database, and providing technical support and maintenance on behalf of and for the account of the legal entity …, it processed the personal data of employees of the legal entity (…), since during the period from … to …, it failed to ensure the conclusion of a valid contract defining the contractual relationship with the processor and regulating the processing by the processor, as required by the third paragraph of Article 28 of the General Regulation, thereby violating the obligation under the third paragraph of Article 28 of the General Data Protection Regulation, which requires that processing by a processor be governed by a contract or other legal act in accordance with Union law or the law of a Member State, which sets out the obligations of the processor in relation to the processing of personal data carried out on behalf of the controller. The offender … committed the offense while performing his or her duties and on behalf of and using the resources of the legal entity …, where he or she was employed as … at the time the offense was committed; consequently, the legal entity … is liable for the aforementioned offense as the responsible legal entity in accordance with the first paragraph of Article 14 of the ZP-1. 2 The legal entity liable for the offender is therefore, pursuant to the first paragraph of Article 95 of ZVOP-2 in conjunction with point (a) of the fourth paragraph of Article 83 of the General Regulation and in application of the third paragraph of Article 52 of the ZP-1, Article 115 of the ZVOP-2, the first and second paragraph","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=IP_(Slovenia)_-_0609-41\u002F2026\u002F7&diff=52677&oldid=52671","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F7\u002F78\u002FLogoSI.png","2026-08-12T07:31:25+00:00","2026-08-12T08:00:17.441639+00:00",7,[18],{"name":19,"type":20},"IP (Slovenia)","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":21,"icon":23,"name":24,"slug":25},{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]