[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiTrUe-CACwp4OZ6WQi-7Ij5oUetwnK4bec8TA02k0Qw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"2dd3f46c-af5d-4a7e-84ee-0ef5c3bff73b","former-employees-retain-data-access-costing-polish-sub-processor-gdpr-fine","ab1bd0c9-00f5-42a9-80b1-354f3ee0f136","Former Employees Retain Data Access, Costing Polish Sub-Processor GDPR Fine","The core failure in this case was the absence of a reliable offboarding process to revoke former employees' access to systems containing customer personal data. By allowing ex-staff to retain access through a shared application, the sub-processor directly violated GDPR principles of integrity, confidentiality, and accountability. This incident also highlights the controller's responsibility to actively oversee its processors — not merely sign data processing agreements and step back. Supply chain data governance is a two-way obligation: controllers must audit processor compliance, and processors must enforce internal controls rigorously. Regulators are increasingly holding the entire data processing chain accountable, meaning a weak link at the sub-processor level can trigger fines and reputational damage across the chain.","**Immediate actions:**\n- Audit all active user accounts against current employee records and immediately revoke access for any former staff.\n- Enforce a formal, documented offboarding checklist that includes same-day revocation of application and data system access.\n\n**Long-term improvements:**\n- Implement automated identity lifecycle management (ILM) tools that deprovision access automatically upon HR system termination events.\n- Establish contractual audit rights and periodic compliance reviews for all data processors and sub-processors.\n- Apply the principle of least privilege so employees only ever access the minimum personal data required for their role.\n\n**Detection & oversight measures:**\n- Schedule quarterly access reviews (access recertification) across all systems handling personal data.\n- Require sub-processors to submit regular evidence of access control audits as part of ongoing controller oversight obligations.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(f) — Integrity and confidentiality principle","GDPR Article 24 — Responsibility of the controller","GDPR Article 28 — Processor obligations and controller oversight","GDPR Article 32 — Security of processing (technical and organisational measures)","CIS Control 5 — Account Management","CIS Control 6 — Access Control Management","NIST SP 800-53 AC-2 — Account Management","NIST SP 800-53 PS-4 — Personnel Termination","NIST SP 800-53 AC-6 — Least Privilege","ISO\u002FIEC 27001:2022 A.5.18 — Access rights","ITIL — Identity and Access Management Practice","published","2026-06-30T10:21:45.14171+00:00","2026-06-30T10:21:45.066+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.7.2022&diff=52014&oldid=52004","uodo-poland-dkn-5131-7-2022-18d2eb","UODO (Poland) - DKN.5131.7.2022",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]