€350K GDPR Fine After Known Vulnerability Left Unpatched
A Greek data controller and processor were fined a combined €350,000 after a known, exploitable technical vulnerability was left unremediated, leading to a data breach. The processor attempted to justify inaction by citing insufficient state funding, but the HDPA firmly rejected this argument, affirming that resource constraints do not waive GDPR security obligations under Article 32. This case underscores that 'known vulnerability' is among the most legally indefensible root causes of a breach — regulators expect timely remediation regardless of organisational size or funding model. Both controllers and processors share accountability for technical security measures, and contractual or financial limitations between parties will not shield either from regulatory consequences.
Tactical Insight
Immediate actions
- Conduct an urgent audit of all known vulnerabilities (CVEs) affecting systems that process personal data and prioritise remediation by exploitability and data sensitivity.
- Apply available patches or deploy compensating controls (e.g., WAF rules, network isolation) for any vulnerability that cannot be immediately patched.
Long-term improvements
- Establish a formal vulnerability management programme with defined SLAs for patching critical findings (e.g., critical CVEs patched within 72 hours).
- Include explicit contractual obligations in Data Processing Agreements (DPAs) requiring processors to maintain patching schedules and report unmitigated vulnerabilities to the controller.
- Build a business case for security investment that references GDPR Article 32 obligations, demonstrating that fines and reputational damage far outweigh modernisation costs.
Detection & compliance measures
- Deploy continuous automated vulnerability scanning across all systems handling personal data and integrate results into a risk register reviewed at board level.
- Conduct annual GDPR Article 32 technical security reviews with documented evidence of remediation decisions to demonstrate accountability to regulators.