[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTWWC7_C2Ty_xOi4bNIj-rfK5u_5GTmPi0kuff8jfdtQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"f0379826-53e9-4121-b939-8cc789a5e19a","105m-gdpr-fine-for-unlawful-data-processing-and-disclosure-failures","93c1d1b1-030b-4cf5-ab8d-3e96db1eda46","€1.05M GDPR Fine for Unlawful Data Processing and Disclosure Failures","Spain's AEPD levied a €1.05 million fine after a company registered a mobile phone line without a valid legal basis, sent personal data in an invoice to an unauthorized email address, and failed to implement adequate technical and organizational security measures — three distinct GDPR failures occurring simultaneously. The root causes point to a breakdown in lawful basis management, poor access and data-sharing controls, and insufficient security governance. These violations highlight that GDPR compliance is not a single checkbox but a continuous operational discipline spanning legal, technical, and procedural domains. Organizations that lack clear data governance frameworks expose themselves not only to regulatory fines but also to reputational damage and loss of customer trust.","**Immediate actions:**\n- Audit all active data processing activities to verify a documented, valid legal basis exists for each one under GDPR Article 6.\n- Review email and document distribution workflows to ensure personal data is only sent to verified, authorized recipients.\n\n**Long-term improvements:**\n- Implement a Data Protection Management System (DPMS) that maps data flows, legal bases, and retention policies across the entire organization.\n- Establish mandatory data protection impact assessments (DPIAs) for any new service or process involving personal data collection or sharing.\n- Enforce role-based access controls and data minimization principles so personal data in invoices or communications is restricted to need-to-know parties.\n\n**Detection & oversight measures:**\n- Appoint or empower a Data Protection Officer (DPO) to conduct regular internal audits and monitor compliance with GDPR obligations.\n- Deploy data loss prevention (DLP) tools to detect and block unauthorized transmission of personal data via email or other channels.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5 (Principles of data processing)","GDPR Article 6 (Lawfulness of processing)","GDPR Article 25 (Data protection by design and by default)","GDPR Article 32 (Security of processing)","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 RA-3 (Risk Assessment)","CIS Control 3 (Data Protection)","CIS Control 6 (Access Control Management)","ISO\u002FIEC 27001:2022 Annex A.5.34 (Privacy and protection of PII)","published","2026-06-18T10:20:32.153698+00:00","2026-06-18T10:20:31.843+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00201-2025&diff=51914&oldid=51912","aepd-spain-ps-00201-2025-927723","AEPD (Spain) - PS-00201-2025",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]