[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f98eG3UE9_JIMzCouHCQlnpEL4Zv-nZI7utssy_awhtg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"6fbabe2d-e4e0-4b80-97d3-a4f8141b39d2","polish-mayor-unlawfully-accessed-employees-facebook-account-violating-gdpr-1782289266845","e4d5f3f8-1d0c-4c38-b919-f08aea2b753b","Polish Mayor Unlawfully Accessed Employee's Facebook Account, Violating GDPR","A Polish mayor accessed a former employee's private Facebook account and used personal conversations as the basis for disciplinary and criminal proceedings, which the Supreme Administrative Court ruled unlawful. The core failure was the complete absence of a valid legal basis for processing personal data, a fundamental GDPR requirement under Article 6. This case illustrates that public officials are not exempt from data protection obligations and that unauthorized access to personal accounts constitutes a serious privacy violation. Beyond the legal consequences, such actions erode institutional trust and expose organizations to significant regulatory and reputational risk.","**Immediate actions:**\n- Establish and document a clear legal basis for any processing of employee personal data before initiating disciplinary or legal proceedings.\n- Revoke access to any organizational accounts belonging to departed employees immediately upon termination.\n\n**Policy & Governance improvements:**\n- Implement a formal Data Protection Impact Assessment (DPIA) process for any investigation involving personal data to ensure GDPR compliance before action is taken.\n- Develop and enforce an Acceptable Use Policy that explicitly prohibits unauthorized access to employees' personal or social media accounts.\n- Appoint or consult a qualified Data Protection Officer (DPO) before using personal data in disciplinary contexts.\n\n**Training & Awareness measures:**\n- Provide mandatory GDPR and privacy law training for all managers and public officials who may handle personal data in HR or disciplinary processes.\n- Conduct regular audits of data access logs to detect and deter unauthorized access to personal or organizational accounts.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5 – Principles relating to processing of personal data","GDPR Article 6 – Lawfulness of processing","GDPR Article 9 – Processing of special categories of personal data","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 PT-2: Authority to Process Personally Identifiable Information","CIS Control 5: Account Management","CIS Control 14: Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 A.5.34 – Privacy and protection of PII","ITIL Service Transition – Change and access management practices","published","2026-06-24T08:21:07.133692+00:00","2026-06-24T08:21:06.698+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NSA_-_III_OSK_2508\u002F25&diff=51962&oldid=51959","nsa-iii-osk-2508-25-efffa0","NSA - III OSK 2508\u002F25",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]