[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOlS9n1M1YVFe21suN4EwPa2MeNzSmXaCZaToACzCjxY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"25c72652-4391-4f91-b5c1-9ccb5e6d3e97","italian-dpa-fines-green-partner-15300-for-gdpr-violations-including-unauthorized-sub-processor-use","8dea7dce-bd91-4333-bc93-2bd9e7a5d6e1","Italian DPA Fines Green Partner €15,300 for GDPR Violations Including Unauthorized Sub-Processor Use","Green Partner violated multiple GDPR obligations by contacting individuals registered on the Public Opt-Out Registry, failing to honor data subject rights requests, and engaging a sub-processor without proper authorization from the data controller, Sorgenia. The root issue reflects a fundamental misunderstanding of the company's role as a data processor and the legal obligations that come with it. This case highlights how the entire data processing chain — including sub-processors — must be governed by explicit contractual authorization and GDPR-compliant practices. Failures at any link in this chain expose both the processor and controller to regulatory liability and reputational harm.","**Immediate actions:**\n- Audit all active marketing lists against national opt-out registries (e.g., Public Opt-Out Registry) before initiating any outreach campaigns.\n- Review all Data Processing Agreements (DPAs) to identify any unauthorized sub-processors and immediately suspend their activities until written authorization is obtained.\n\n**Compliance & governance improvements:**\n- Establish a formal sub-processor onboarding process that requires explicit written approval from the data controller before engagement.\n- Train all staff involved in data processing on their specific legal role (controller vs. processor) and the obligations that apply to each under GDPR Articles 28–29.\n- Implement a documented data subject rights handling procedure with defined SLAs to ensure timely and compliant responses to access, erasure, and objection requests.\n\n**Monitoring & accountability measures:**\n- Schedule periodic GDPR compliance audits covering sub-processor relationships, consent records, and opt-out registry checks.\n- Assign a dedicated Data Protection Officer (DPO) or compliance owner responsible for monitoring regulatory changes and ensuring ongoing adherence to data processing obligations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 6 – Lawfulness of processing","GDPR Article 17 – Right to erasure","GDPR Article 21 – Right to object","GDPR Article 28 – Processor obligations and sub-processor authorization","GDPR Article 29 – Processing under authority of controller","NIST SP 800-53 PT-1 (Privacy Policy and Procedures)","NIST SP 800-53 SA-9 (External System Services \u002F Supply Chain)","CIS Control 3 – Data Protection","CIS Control 17 – Incident Response Management","ISO\u002FIEC 27701 – Privacy Information Management (PIMS)","published","2026-08-19T08:20:32.016922+00:00","2026-08-19T08:20:31.934+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_10266250&diff=52732&oldid=52723","garante-per-la-protezione-dei-dati-personali-italy-10266250-cbd00c","Garante per la protezione dei dati personali (Italy) - 10266250",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]