[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5XcasomdDjLs5HigovFTTlBqr2rhQ3nrNrNEuMt5NE8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"2f46f062-9ce4-49e2-abef-5d4773a86560","italian-firm-fined-6500-for-failing-to-deactivate-ex-employee-accounts-and-gdpr-violations","3d33f3f2-780d-49ff-ab4f-11d27e79a9b3","Italian Firm Fined €6,500 for Failing to Deactivate Ex-Employee Accounts and GDPR Violations","Top Secret Investigazioni e sicurezza s.r.l. failed to deactivate former employees' company accounts in a timely manner, a fundamental access control failure that left personal data exposed and processing operations non-compliant with GDPR. Compounding the issue, email forwarding was misconfigured and non-functional for eight months, meaning the organization had no clear oversight of data flows during that period. These failures directly violated GDPR's data minimization and storage limitation principles, which require that personal data is only processed to the extent necessary and not retained beyond its purpose. This case underscores that even small investigative firms handling sensitive personal data must maintain rigorous offboarding procedures and data governance controls.","**Immediate actions:**\n- Establish a formal offboarding checklist that mandates immediate deactivation of all company accounts upon employee departure.\n- Audit all active email forwarding rules and shared mailbox configurations to verify they are functioning correctly and are documented.\n\n**Long-term improvements:**\n- Implement an Identity and Access Management (IAM) solution that automates account lifecycle management, including scheduled access reviews.\n- Define and enforce a data retention policy aligned with GDPR principles, ensuring personal data is deleted or anonymized once its purpose is fulfilled.\n- Integrate HR offboarding workflows directly with IT systems to ensure access revocation is triggered automatically on the last day of employment.\n\n**Detection & Compliance measures:**\n- Schedule quarterly access reviews to identify and remove dormant or orphaned accounts across all systems.\n- Maintain an auditable log of account creation, modification, and deactivation events to support GDPR accountability obligations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(c) – Data Minimisation","GDPR Article 5(1)(e) – Storage Limitation","GDPR Article 5(2) – Accountability Principle","GDPR Article 24 – Responsibility of the Controller","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 AC-17 – Remote Access","ISO\u002FIEC 27001 A.9.2.6 – Removal or Adjustment of Access Rights","ITIL Service Transition – Identity and Access Management Process","published","2026-09-10T14:20:45.332877+00:00","2026-09-10T14:20:45.012+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_554\u002F2026&diff=52994&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-554-2026-3ee237","Garante per la protezione dei dati personali (Italy) - 554\u002F2026",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]