[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1tQ0l4qq3_XGr49O0xUoelVFNDrD4mg4eBYfEqYOhZ8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"5026e437-bb40-4666-a50b-aa01d55ddba6","iberia-fined-650k-for-data-breach-and-notification-failures","2d5f7fc0-d252-4a2e-9e99-c9b56429177c","Iberia Fined €650K for Data Breach and Notification Failures","Iberia was penalized by Spain's AEPD for inadequate security measures at a data processor that led to a cross-border EU data breach, violating GDPR's integrity and confidentiality requirements. The airline also failed to notify affected individuals about the breach, demonstrating poor incident response procedures. This case highlights that organizations remain liable for their processors' security failures and must have robust data protection controls throughout their supply chain. The significant fine emphasizes regulators' focus on both preventing breaches and ensuring proper breach notification procedures.","**Immediate actions:**\n- Conduct security audits of all data processors and third-party vendors handling personal data\n- Implement contractual requirements for processors to meet GDPR security standards\n- Establish incident notification procedures to contact data subjects within 72 hours of breach discovery\n\n**Long-term improvements:**\n- Deploy continuous monitoring of data processing activities across all vendors and subsidiaries\n- Create comprehensive data mapping to identify all personal data flows and processing locations\n- Develop automated breach detection and notification systems integrated with processor environments\n\n**Compliance measures:**\n- Implement regular GDPR compliance assessments including processor oversight requirements\n- Establish legal frameworks ensuring processors report breaches immediately to data controllers\n- Train staff on cross-border data protection requirements and notification timelines",[12,13,14,15,16,17,18],"GDPR Article 32","GDPR Article 28","GDPR Article 34","GDPR Article 33","NIST Privacy Framework PR.DS-1","CIS Control 3","ISO 27001 A.15.1.1","published","2026-06-09T14:20:36.038164+00:00","2026-06-09T14:20:35.752+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00437-2024&diff=51847&oldid=51792","aepd-spain-ps-00437-2024-4cbb8d","AEPD (Spain) - PS-00437-2024",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":34,"name":35,"slug":36,"description":37,"color":38},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]