[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH53kyXbw5tKOx8zQhyyvzQmGwLJCaSvRdER1TE2S2Jg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"f6701810-1eba-4382-9d1f-30e8e0b25892","eu-commission-fined-50k-for-unlawful-personal-data-in-anti-fraud-press-release","817c87d8-f52a-4303-bb13-172b72bc6884","EU Commission Fined €50K for Unlawful Personal Data in Anti-Fraud Press Release","The European Commission was ordered to pay €50,000 in damages after publishing a press release containing unnecessary and inaccurate personal data about an individual involved in an anti-fraud investigation. This case highlights that even official institutional communications must adhere strictly to data minimisation and accuracy principles under EU data protection law. Publishing more personal information than is required for a legitimate purpose constitutes unlawful processing, regardless of the public interest nature of the underlying activity. The ruling underscores that data protection obligations apply equally to EU institutions and private organisations, and that reputational and financial harm caused by inaccurate disclosures carries real legal consequences.","**Immediate actions:**\n- Establish a mandatory data protection review process for all external communications, press releases, and public-facing documents before publication.\n- Remove or anonymise personal data in draft communications that is not strictly necessary to convey the intended message.\n\n**Policy & governance improvements:**\n- Implement a Data Protection by Design and by Default (DPbD) policy requiring privacy impact assessments (DPIAs) for any public disclosure involving personal data.\n- Appoint a designated Data Protection Officer (DPO) reviewer as a required sign-off stakeholder for institutional press releases and investigation disclosures.\n- Establish clear data minimisation guidelines defining what categories of personal data are permissible in public communications related to investigations.\n\n**Training & awareness measures:**\n- Train communications, legal, and compliance staff on GDPR\u002FEU Regulation 2018\u002F1725 data minimisation and accuracy principles specific to public disclosures.\n- Run periodic simulated review exercises where teams assess draft communications for unlawful personal data exposure.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 5(1)(d) – Accuracy","GDPR Article 82 – Right to Compensation and Liability","EU Regulation 2018\u002F1725 – Data Protection for EU Institutions","NIST SP 800-53 IP-1 (Individual Participation Policy)","NIST SP 800-53 SI-12 (Information Management and Retention)","CIS Control 3 – Data Protection","ISO\u002FIEC 29101 – Privacy Architecture Framework","ITIL Service Transition – Communication Management","published","2026-07-29T14:20:40.310367+00:00","2026-07-29T14:20:40.191+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_T%E2%80%91384\u002F20_RENV_-_OC_v_Commission&diff=52555&oldid=52266","cjeu-t-384-20-renv-oc-v-commission-be1de9","CJEU - T‑384\u002F20 RENV - OC v Commission",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]