[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSrIsmjmSWTd5ASVeYQlYXoGdiB8DhJm21YtN682z488":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"3acfd07a-217b-480f-8f8b-fa39a5126852","italian-garante-finds-gdpr-violation-in-cross-border-b2b-contact-profiling","d8cd8e01-f80d-483a-90ca-b5fdd255391a","Italian Garante Finds GDPR Violation in Cross-Border B2B Contact Profiling","A non-EU controller was found to have violated GDPR by collecting and combining personal data from multiple sources — including public datasets and commercial partners — to build detailed profiles of individuals classified as business contacts. The controller incorrectly assumed that its non-EU establishment and B2B focus exempted it from GDPR obligations, which is a common but dangerous misconception. GDPR applies extraterritorially whenever data subjects are in the EU, regardless of where the controller is based or whether the context is commercial. This case underscores that aggregating even seemingly innocuous business contact data can constitute significant personal data processing requiring a lawful basis, transparency, and full GDPR compliance.","**Immediate actions:**\n- Conduct a rapid audit of all personal data collected from EU residents to determine whether a valid GDPR lawful basis exists for each processing activity.\n- Appoint an EU-based Data Protection Representative if your organization processes EU personal data from outside the EU, as required by GDPR Article 27.\n\n**Compliance & governance improvements:**\n- Maintain a comprehensive Record of Processing Activities (RoPA) under GDPR Article 30 that documents all data sources, purposes, and legal bases, including data sourced from third-party commercial partners.\n- Establish a formal Data Protection Impact Assessment (DPIA) process for any profiling or data aggregation activities involving EU individuals.\n- Train legal, product, and data teams on GDPR's extraterritorial scope to prevent erroneous assumptions about B2B or non-EU exemptions.\n\n**Third-party & supply chain data controls:**\n- Vet all commercial data partners for GDPR compliance and establish Data Processing Agreements (DPAs) before ingesting any personal data.\n- Implement data minimization policies to limit the combination of data from multiple sources only to what is strictly necessary for the stated purpose.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 3 (Territorial Scope)","GDPR Article 5 (Principles of Processing)","GDPR Article 6 (Lawful Basis for Processing)","GDPR Article 13\u002F14 (Transparency & Information Obligations)","GDPR Article 27 (Representatives of Controllers Not Established in the EU)","GDPR Article 28 (Processor Agreements)","GDPR Article 30 (Records of Processing Activities)","GDPR Article 35 (Data Protection Impact Assessment)","NIST Privacy Framework PR.DS-P1 (Data Management)","NIST SP 800-53 PT-1 (Personally Identifiable Information Processing Policies)","CIS Control 3 (Data Protection)","ISO\u002FIEC 27701 (Privacy Information Management)","published","2026-08-04T12:22:16.710926+00:00","2026-08-04T12:22:16.613+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542\u002F2026&diff=52592&oldid=52583","garante-per-la-protezione-dei-dati-personali-italy-542-2026-31e5f6","Garante per la protezione dei dati personali (Italy) - 542\u002F2026",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]