Italian Firm Fined €6,500 for Failing to Deactivate Ex-Employee Accounts and GDPR Violations
Top Secret Investigazioni e sicurezza s.r.l. failed to deactivate former employees' company accounts in a timely manner, a fundamental access control failure that left personal data exposed and processing operations non-compliant with GDPR. Compounding the issue, email forwarding was misconfigured and non-functional for eight months, meaning the organization had no clear oversight of data flows during that period. These failures directly violated GDPR's data minimization and storage limitation principles, which require that personal data is only processed to the extent necessary and not retained beyond its purpose. This case underscores that even small investigative firms handling sensitive personal data must maintain rigorous offboarding procedures and data governance controls.
Tactical Insight
Immediate actions
- Establish a formal offboarding checklist that mandates immediate deactivation of all company accounts upon employee departure.
- Audit all active email forwarding rules and shared mailbox configurations to verify they are functioning correctly and are documented.
Long-term improvements
- Implement an Identity and Access Management (IAM) solution that automates account lifecycle management, including scheduled access reviews.
- Define and enforce a data retention policy aligned with GDPR principles, ensuring personal data is deleted or anonymized once its purpose is fulfilled.
- Integrate HR offboarding workflows directly with IT systems to ensure access revocation is triggered automatically on the last day of employment.
Detection & Compliance measures
- Schedule quarterly access reviews to identify and remove dormant or orphaned accounts across all systems.
- Maintain an auditable log of account creation, modification, and deactivation events to support GDPR accountability obligations.