Back to all lessons
Awareness Lessons
2 months ago

Slovenia Fines Company for Missing GDPR Data Processing Agreement with Service Provider

A Slovenian company was fined €1,282 after failing to establish a formal Data Processing Agreement (DPA) with a third-party service provider handling employee personal data, violating GDPR Article 28(3). The root cause was a lack of governance oversight by the data controller's legal representative, who neglected to formalize the contractual relationship before data processing began. This matters because Article 28(3) is a mandatory legal safeguard — without a DPA, data subjects lose contractual protections over how their personal data is handled by processors. Even smaller fines signal regulatory intent to enforce third-party data governance rigorously, and repeat failures could attract much larger penalties.

Tactical Insight

Immediate actions

  • Audit all existing third-party service providers to confirm valid, signed Data Processing Agreements are in place before any personal data is shared.
  • Suspend or restrict personal data flows to any vendor lacking a compliant DPA until the agreement is executed.

Long-term improvements

  • Maintain a formal Vendor/Processor Register that tracks DPA status, review dates, and data categories processed for every third-party relationship.
  • Embed DPA execution as a mandatory gate in the vendor onboarding workflow so no personal data transfer can proceed without a signed agreement.
  • Assign a designated Data Protection Officer or compliance role with ownership over periodic DPA reviews and renewals.

Awareness & governance measures

  • Train legal representatives and procurement staff on GDPR Article 28 obligations so they understand the mandatory nature of DPAs.
  • Implement an annual compliance check against all active data processor relationships to identify and remediate contractual gaps.