Back to all lessons
Awareness Lessons
2 weeks ago

MEP Fined for Failing to Cooperate with DPA Investigation into Data-Heavy Platform

The core failure here was a deliberate refusal to cooperate with a supervisory authority and an inadequate Data Protection Impact Assessment (DPIA) for a platform processing highly sensitive data including political opinions and biometric information. Under GDPR, conducting a thorough DPIA before processing high-risk data is mandatory, not optional, and cooperation with Data Protection Authorities (DPAs) is an independent legal obligation regardless of the data controller's status or position. Submitting an incomplete DPIA signals a fundamental gap in privacy-by-design practices and risk management culture. This case matters because it demonstrates that no individual or organization—regardless of political standing—is exempt from GDPR obligations, and non-cooperation compounds regulatory penalties significantly.

Tactical Insight

Immediate actions

  • Conduct a complete and thorough DPIA before launching any platform that processes special category data such as biometric or political opinion data.
  • Respond promptly and fully to all DPA inquiries, requests, and investigative procedures to avoid compounding violations.

Data governance improvements

  • Establish a formal data protection governance framework that assigns clear ownership for DPIA completion, review, and submission.
  • Implement a legal and compliance review gate that must be passed before any high-risk data processing platform goes live.
  • Appoint or consult a qualified Data Protection Officer (DPO) to oversee compliance with GDPR obligations on an ongoing basis.

Long-term compliance measures

  • Schedule periodic audits of all active platforms processing special category data to ensure continued GDPR compliance.
  • Train all staff and stakeholders involved in platform operations on their obligations under GDPR Articles 35–36 (DPIA) and Article 31 (cooperation with supervisory authorities).
  • Maintain documented records of DPA correspondence and compliance activities to demonstrate accountability under GDPR Article 5(2).