[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-gib2tvT-l5Id_YbQ3gtpcP3ZqvQYWSB385L2DWIpOI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"6d1bdf11-26ca-4571-91a5-827969f40e9d","greek-municipality-fined-for-gdpr-violations-in-employee-data-publication","d41c31c3-3875-4bf4-86b4-9f2095e06870","Greek Municipality Fined for GDPR Violations in Employee Data Publication","A Greek municipal body violated GDPR by publishing employee details on a public transparency portal that allowed for individual identification through initials and employment information. The organization compounded the violation by failing to respond to the employee's legitimate erasure request. This case demonstrates how well-intentioned transparency initiatives can become privacy violations when proper data protection safeguards are not implemented. Organizations must balance transparency obligations with privacy rights by implementing data minimization and anonymization techniques.","**Immediate actions:**\n- Review all public-facing portals and websites for personally identifiable information\n- Establish clear procedures for handling data subject rights requests including erasure\n- Remove or properly anonymize any published data that could lead to individual identification\n\n**Long-term improvements:**\n- Implement data protection impact assessments before publishing any employee or citizen data\n- Develop anonymization and pseudonymization standards for transparency reporting\n- Create regular training programs on GDPR compliance for staff handling public records\n\n**Governance measures:**\n- Designate clear roles and responsibilities for data protection compliance\n- Establish automated tracking systems for data subject rights requests with defined response timeframes\n- Conduct quarterly reviews of all public data publications against privacy requirements",[12,13,14,15,16,17,18],"GDPR Article 6","GDPR Article 17","GDPR Article 25","GDPR Article 32","CIS Control 3","NIST Privacy Framework PR.IP-2","ISO 27001 A.18.1.4","published","2026-06-09T10:20:34.843074+00:00","2026-06-09T10:20:34.76+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=%CE%A3%CF%84%CE%95_-_442\u002F2026&diff=51842&oldid=0","442-2026-93ac15","ΣτΕ - 442\u002F2026",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":34,"name":35,"slug":36,"description":37,"color":38},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]