Back to all lessons
Awareness Lessons
3 months ago

Greek College Fined for Failing to Honor Employee Data Subject Rights

The American College of Greece violated GDPR obligations by only partially fulfilling a former employee's data access request and missing legally mandated response deadlines for both access and erasure requests. This case highlights that data subject rights are not merely procedural formalities — organizations must respond fully and on time or face regulatory penalties. Failing to track and manage Data Subject Access Requests (DSARs) within the required one-month window (extendable to three months in complex cases) is a compliance failure that regulators take seriously. Even relatively small organizations are not exempt from enforcement, and fines can be issued per violation, meaning multiple failures compound the financial and reputational risk.

Tactical Insight

Immediate actions

  • Establish a formal DSAR (Data Subject Access Request) intake process with a centralized register to log, track, and timestamp every request upon receipt.
  • Audit all current open or historical data subject requests to identify any outstanding or partially fulfilled obligations.

Process & Policy improvements

  • Define clear internal SLAs and assign ownership roles for processing access, erasure, and rectification requests within GDPR's one-month deadline.
  • Create response templates and escalation procedures to ensure complete — not partial — fulfillment of data subject rights requests.
  • Train HR and legal staff specifically on GDPR data subject rights obligations, including the consequences of missed deadlines.

Long-term improvements

  • Implement a dedicated privacy management platform (e.g., OneTrust, TrustArc) to automate DSAR workflows and deadline tracking.
  • Conduct annual GDPR compliance audits covering data subject rights handling to proactively identify gaps before regulatory scrutiny.