[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjynPlt9_5Nu3v2XVC0gpRclcdivgCaVv3LPRGciXlLw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"ef1c0d96-ec74-4c6e-98c5-d7292e9a6b7a","gdpr-breach-unauthorized-disclosure-of-personal-data-via-facebook-message","dfccd53d-5fb6-4818-bd9d-497b0ebc3b1f","GDPR Breach: Unauthorized Disclosure of Personal Data via Facebook Message","A Dutch company violated GDPR by sharing a journalist's personal data through a Facebook message to a third party without a lawful basis, breaching Articles 5(1)(f), 6, and 32(2). The core failure was the absence of consent or any other valid legal ground for processing and disclosing personal data, combined with the use of an insecure, informal channel (Facebook) for transmitting sensitive information. This case illustrates that even well-intentioned disclosures — such as initiating legal proceedings — must be grounded in a lawful basis and conducted through secure, controlled mechanisms. The ruling reinforces that loss of control over personal data, regardless of intent or scale, constitutes a GDPR violation with legal consequences.","**Immediate actions:**\n- Audit all current processes where personal data is shared with third parties and verify each has a documented lawful basis under GDPR Article 6.\n- Prohibit the use of personal or informal communication channels (e.g., Facebook, personal email) for transmitting any personal data.\n- Train staff immediately on the requirement to obtain Data Protection Officer (DPO) or legal review before disclosing personal data externally.\n\n**Long-term improvements:**\n- Implement a formal Data Sharing Agreement (DSA) process requiring documented justification and approval before any third-party data disclosure.\n- Establish a Data Classification Policy that mandates secure, encrypted channels for all personal data transfers.\n- Embed privacy-by-design principles into business processes, especially those involving legal or enforcement actions.\n\n**Detection & Compliance measures:**\n- Maintain a data processing register (Article 30 record) that logs all instances of personal data sharing, including the recipient, purpose, and legal basis.\n- Conduct periodic GDPR compliance audits to identify unauthorized or undocumented data flows within the organization.\n- Implement Data Loss Prevention (DLP) tools to detect and alert on personal data being transmitted via unauthorized platforms.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 5(1)(f) — Integrity and confidentiality principle","GDPR Article 6 — Lawfulness of processing","GDPR Article 32(2) — Security of processing","GDPR Article 30 — Records of processing activities","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 MP-5: Media Transport","NIST Privacy Framework PR.DS-P5: Data retention and disposal","CIS Control 3: Data Protection","CIS Control 14: Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 Annex A 5.33 — Protection of records","ISO\u002FIEC 27701 — Privacy Information Management System (PIMS)","published","2026-06-24T12:22:04.08868+00:00","2026-06-24T12:22:03.942+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Rb._Noord-Nederland_-_C\u002F_18\u002F189406\u002FHA_ZA_19-6&diff=51992&oldid=24540","rb-noord-nederland-c-18-189406-ha-za-19-6-c62c26","Rb. Noord-Nederland - C\u002F 18\u002F189406\u002FHA ZA 19-6",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]