[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWSOeUdFuxEpCwSekNNQ_3jOA_ic6Huy-bHYju2P4g2Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"663c9661-6147-4aa9-8914-7b19c2e6ab3d","former-employees-retain-data-access-after-departure-triggering-gdpr-fine","5823d5fe-97ef-4ccc-9be6-56e02752cc27","Former Employees Retain Data Access After Departure, Triggering GDPR Fine","A Polish sub-processor failed to revoke application access for former employees, allowing them to continue viewing customer personal data after their employment ended. This constitutes both an access control failure and a breach of GDPR Article 32, which mandates appropriate technical and organizational measures to protect personal data. Compounding the issue, the data controller failed to verify that the processor had adequate safeguards in place and did not establish sufficiently robust data protection agreements. This case illustrates that GDPR accountability extends across the entire processor chain — controllers cannot delegate responsibility without active oversight. Offboarding procedures and processor audits are not optional compliance niceties; they are legally required safeguards.","**Immediate actions:**\n- Audit all active application accounts and immediately revoke access for any former or inactive employees.\n- Review all data processing agreements (DPAs) with sub-processors to ensure they meet GDPR Article 28 requirements.\n\n**Long-term improvements:**\n- Integrate automated account deprovisioning into the HR offboarding workflow so access is revoked on the employee's last working day.\n- Establish a formal processor compliance review program that includes periodic audits of sub-processors' technical and organizational measures.\n- Implement role-based access control (RBAC) with least-privilege principles to minimize data exposure across all applications.\n\n**Detection & monitoring measures:**\n- Deploy user activity monitoring on applications containing personal data to flag access by accounts that should no longer be active.\n- Schedule quarterly access reviews to identify and remediate orphaned or excessive user accounts across all systems handling personal data.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 28 – Processor obligations and data processing agreements","GDPR Article 32 – Security of processing","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 PS-4 – Personnel Termination","NIST SP 800-53 CA-2 – Control Assessments (for processor audits)","ISO\u002FIEC 27001:2022 A.5.18 – Access rights","ISO\u002FIEC 27001:2022 A.6.5 – Responsibilities after termination or change of employment","published","2026-06-30T18:21:12.827197+00:00","2026-06-30T18:21:12.538+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.7.2022&diff=52031&oldid=52014","uodo-poland-dkn-5131-7-2022-f09db3","UODO (Poland) - DKN.5131.7.2022",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]