[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxeueRDtS0A9x6VtLslsbf7aNERaae-5duUVyZzTgedQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"25edcb4f-2daa-48c9-a8f4-97346e069252","italian-utility-fined-15000-for-gdpr-violations-in-data-processing-operations","56e05e3d-bd42-4b1c-9acf-f8db722154ce","Italian Utility Fined €15,000 for GDPR Violations in Data Processing Operations","Nuova Corrente S.r.l. failed to maintain proper accountability and control over personal data processing operations, particularly when delegating responsibilities to third-party processors. The company provided contradictory information about data sources, inadequately responded to data subject access requests, and allowed processors to transfer personal data without respecting individual consent preferences. This case demonstrates that organizations remain fully liable for GDPR compliance even when outsourcing data processing activities to third parties. The violations affected multiple data subjects and resulted in regulatory enforcement action, highlighting the importance of maintaining clear data governance frameworks.","**Immediate actions:**\n- Conduct audit of all current data processing activities and third-party processor agreements\n- Review and update data subject request response procedures to ensure GDPR compliance\n- Implement controls to prevent unauthorized data transfers by processors\n\n**Long-term improvements:**\n- Establish clear accountability frameworks defining controller and processor responsibilities\n- Develop comprehensive data governance policies covering collection, processing, and transfer activities\n- Create regular compliance monitoring processes for all data processing operations\n\n**Governance measures:**\n- Implement mandatory GDPR training for staff handling personal data decisions\n- Establish legal review processes for all new data processing activities and processor contracts",[12,13,14,15,16,17],"GDPR Article 5","GDPR Article 24","GDPR Article 28","GDPR Article 15","ISO 27001 A.18.1.4","NIST Privacy Framework PR.AC-P","published","2026-06-09T12:21:28.418737+00:00","2026-06-09T12:21:28.342+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_312\u002F2026&diff=51844&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-312-2026-b6220c","Garante per la protezione dei dati personali (Italy) - 312\u002F2026",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]