[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4kynZ3YlIQiLlBtYE1ZwPDO5jKNeCA-Gv9909Vl2uts":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"6754bd4f-7abb-4399-9f03-60e433bd6973","italian-school-fined-10000-for-over-sharing-dismissed-employees-disciplinary-data","a005d5df-b514-4bee-aea1-2e9929659081","Italian School Fined €10,000 for Over-Sharing Dismissed Employees' Disciplinary Data","A school in Italy violated GDPR by sharing detailed disciplinary proceedings of dismissed employees with other branches, far exceeding what was necessary for any legitimate purpose. This breach of the data minimization and purpose limitation principles (Articles 5(1)(b) and 5(1)(c) GDPR) demonstrates a failure to assess the legal basis and proportionality of internal data sharing practices. The DPA clarified that employers can independently verify prior dismissal declarations, making broad inter-branch notification unjustifiable. This case underscores that even internal, administrative data flows must be grounded in a clear legal obligation and limited to what is strictly necessary.","**Immediate actions:**\n- Conduct an urgent review of all internal HR data-sharing workflows to ensure they are limited to recipients with a documented need-to-know.\n- Establish a documented legal basis for every category of personal data processed, especially sensitive employee information.\n\n**Long-term improvements:**\n- Implement a Data Protection Impact Assessment (DPIA) process for any HR procedure that involves sharing personal data across departments or branches.\n- Train HR and administrative staff on GDPR data minimization and purpose limitation principles at least annually.\n- Develop and enforce a formal HR Data Sharing Policy that defines permissible disclosures and approvals required for exceptions.\n\n**Detection & Governance measures:**\n- Appoint or empower a Data Protection Officer (DPO) to audit internal data flows on a regular schedule and flag non-compliant practices.\n- Maintain a Record of Processing Activities (RoPA) that is reviewed and updated whenever HR processes change.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(b) – Purpose Limitation","GDPR Article 5(1)(c) – Data Minimization","GDPR Article 6 – Lawfulness of Processing","GDPR Article 35 – Data Protection Impact Assessment","GDPR Article 30 – Records of Processing Activities","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","CIS Control 3 – Data Protection","ISO\u002FIEC 27001:2022 Annex A 5.34 – Privacy and Protection of PII","ITIL Service Management – Information Security Policy","published","2026-09-09T12:21:31.177427+00:00","2026-09-09T12:21:30.849+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_553\u002F2026&diff=52984&oldid=52983","garante-per-la-protezione-dei-dati-personali-italy-553-2026-73bcaa","Garante per la protezione dei dati personali (Italy) - 553\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]