[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBNhQdMqczN6xBB2XBUu5ZNMhydW1vMc95_43l-jaIhw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"89f1f45e-be39-42d1-a0a8-e61d0ea46d13","italian-dpa-fines-controller-5000-for-unlawful-employee-data-disclosure-to-employer","2123b4d9-df88-46bf-b7dd-efce3c45888d","Italian DPA Fines Controller €5,000 for Unlawful Employee Data Disclosure to Employer","A controller unlawfully forwarded a data subject's personal complaint — including their identity and unrelated disciplinary history — to their employer without a valid legal basis, violating GDPR Articles 5 and 6. This breach demonstrates a fundamental failure to apply purpose limitation and data minimization principles before sharing personal information with third parties. The disclosure exposed the individual to potential workplace harm and highlights how informal or ad hoc data sharing decisions, made without proper legal review, can constitute serious GDPR violations. Organizations must treat every act of data disclosure as a deliberate, documented decision grounded in a legitimate legal basis.","**Immediate actions:**\n- Establish a mandatory legal basis review checklist that staff must complete before sharing any personal data with third parties, including employers.\n- Audit all current data-sharing practices and workflows to identify instances where personal data is disclosed without documented legal justification.\n\n**Process & Policy improvements:**\n- Implement a Data Sharing Agreement (DSA) or formal authorization process for any disclosure of personal data to external parties.\n- Train all staff handling personal data on GDPR principles — especially purpose limitation, data minimization, and lawful basis — with role-specific scenarios.\n- Create a clear escalation path to the Data Protection Officer (DPO) for any non-routine data disclosure requests before action is taken.\n\n**Detection & Accountability measures:**\n- Maintain detailed logs of all third-party data disclosures, including the legal basis cited, date, recipient, and data categories shared.\n- Conduct periodic internal audits or DPO reviews of data-sharing incidents to detect and correct unlawful disclosure patterns before regulatory action occurs.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(b) – Purpose Limitation","GDPR Article 5(1)(c) – Data Minimization","GDPR Article 6 – Lawfulness of Processing","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 IP-1 – Consent","NIST Privacy Framework PR.PO-P1 – Policies for data processing","CIS Control 3 – Data Protection","ISO\u002FIEC 27001:2022 A.5.34 – Privacy and protection of personal data","ITIL Service Design – Information Security Management","published","2026-09-28T18:23:05.697535+00:00","2026-09-28T18:23:05.405+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_615\u002F2026&diff=53200&oldid=53199","garante-per-la-protezione-dei-dati-personali-italy-615-2026-e76996","Garante per la protezione dei dati personali (Italy) - 615\u002F2026",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]