[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3Z1RLVD9FpTo4NpIcXxrebguHTgy5fZask6wpo-EcRg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"4546706b-6da3-4218-b60a-536f6fa718e2","media-company-fined-140k-for-publishing-links-to-breached-personal-data","af1d7656-7046-4aa8-ae02-e0dcfeb9f3d5","Media Company Fined €140K for Publishing Links to Breached Personal Data","Mediaworks Hungary was fined for publishing articles containing hyperlinks to an interactive map exposing personal data of 200,000 individuals from a data breach. The company failed to recognize that linking to compromised personal data constitutes unlawful processing under GDPR, even when claiming journalistic freedom. This case demonstrates that organizations cannot simply link to breached data and claim editorial protection - they must evaluate the lawfulness of data processing before publication. The ruling establishes that indirect access to personal data through hyperlinks still triggers GDPR compliance obligations.","**Editorial controls:**\n- Implement mandatory data protection review process before publishing any content containing personal information\n- Train editorial staff to recognize when content may contain unlawfully processed personal data\n- Establish clear guidelines prohibiting links to known data breach content\n\n**Legal safeguards:**\n- Conduct GDPR Article 6 lawful basis assessment before publishing any personal data\n- Develop incident response procedures for handling requests to remove problematic content\n- Maintain documentation of editorial decisions involving personal data processing\n\n**Technical measures:**\n- Deploy content scanning tools to detect potential personal data in articles before publication\n- Implement editorial workflow systems requiring data protection approval for sensitive content",[12,13,14,15,16],"GDPR Article 6(1)","GDPR Article 5","GDPR Article 24","CIS Control 14","NIST PR.DS-3","published","2026-05-28T12:20:40.225636+00:00","2026-05-28T12:20:40.127+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NAIH_(Hungary)_-_NAIH\u002F962-10\u002F2026&diff=51756&oldid=0","naih-hungary-naih-962-10-2026-32a76e","NAIH (Hungary) - NAIH\u002F962-10\u002F2026",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]