EU Commission Fined €50K for Unlawful Personal Data in Anti-Fraud Press Release
The European Commission was ordered to pay €50,000 in damages after publishing a press release containing unnecessary and inaccurate personal data about an individual involved in an anti-fraud investigation. This case highlights that even official institutional communications must adhere strictly to data minimisation and accuracy principles under EU data protection law. Publishing more personal information than is required for a legitimate purpose constitutes unlawful processing, regardless of the public interest nature of the underlying activity. The ruling underscores that data protection obligations apply equally to EU institutions and private organisations, and that reputational and financial harm caused by inaccurate disclosures carries real legal consequences.
Tactical Insight
Immediate actions
- Establish a mandatory data protection review process for all external communications, press releases, and public-facing documents before publication.
- Remove or anonymise personal data in draft communications that is not strictly necessary to convey the intended message.
Policy & governance improvements
- Implement a Data Protection by Design and by Default (DPbD) policy requiring privacy impact assessments (DPIAs) for any public disclosure involving personal data.
- Appoint a designated Data Protection Officer (DPO) reviewer as a required sign-off stakeholder for institutional press releases and investigation disclosures.
- Establish clear data minimisation guidelines defining what categories of personal data are permissible in public communications related to investigations.
Training & awareness measures
- Train communications, legal, and compliance staff on GDPR/EU Regulation 2018/1725 data minimisation and accuracy principles specific to public disclosures.
- Run periodic simulated review exercises where teams assess draft communications for unlawful personal data exposure.