[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsDfX1m8f8WvJwOpyvqfjm05m5sMkLp32ZzzNcruCYK8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"e5e56272-3327-4753-9c76-ae066d399fa9","finland-dpa-reprimands-controller-for-unlawful-publication-of-suspended-athletes-personal-data","c2897e6f-38f3-4eb7-b92d-29dc35ea38fe","Finland DPA Reprimands Controller for Unlawful Publication of Suspended Athletes' Personal Data","A Finnish controller published a list of suspended athletes without a valid legal basis, violating core GDPR principles including lawfulness, fairness, transparency, and data minimization. The root cause was a failure to establish and verify an appropriate legal basis before publicly disclosing personal data — a foundational requirement under GDPR Article 6. This case is significant because it confirms that anti-doping infringement data falls within GDPR's scope, as affirmed by a CJEU ruling, meaning sports organizations cannot assume special exemptions apply. Publishing more personal data than necessary, and without proper justification, exposes both the individuals affected and the organization to serious legal and reputational consequences. Controllers must treat public disclosures of personal data with the same rigor as any other high-risk processing activity.","**Immediate actions:**\n- Audit all existing public-facing publications of personal data to verify a documented and valid legal basis exists for each.\n- Remove or restrict access to any published personal data where a lawful basis cannot be confirmed until a full legal review is completed.\n\n**Policy & Governance improvements:**\n- Implement a mandatory Privacy Impact Assessment (PIA) process that must be completed before any personal data is published publicly.\n- Establish a data minimization checklist requiring review of whether each data field in a publication is strictly necessary for the stated purpose.\n- Define and document internal approval workflows requiring Data Protection Officer (DPO) sign-off prior to public disclosure of personal data.\n\n**Training & Awareness measures:**\n- Train all staff involved in communications and publishing on GDPR legal bases (Article 6) and the specific risks of public data disclosure.\n- Conduct annual GDPR compliance refresher sessions that include real-world enforcement cases to reinforce accountability.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) — Lawfulness, fairness, and transparency","GDPR Article 5(1)(c) — Data minimisation","GDPR Article 6 — Lawfulness of processing","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","GDPR Article 37-39 — Data Protection Officer obligations","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 PT-3 (Personally Identifiable Information Processing Purposes)","CIS Control 3 — Data Protection","ISO\u002FIEC 27701:2019 — Privacy Information Management (PIMS)","ITIL Service Design — Information Security Management","published","2026-08-25T10:20:35.473623+00:00","2026-08-25T10:20:35.401+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Tietosuojavaltuutetun_toimisto_(Finland)_-_TSV\u002F179\u002F2021&diff=52770&oldid=52769","tietosuojavaltuutetun-toimisto-finland-tsv-179-2021-d98475","Tietosuojavaltuutetun toimisto (Finland) - TSV\u002F179\u002F2021",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]