Slovenia Fines Company for Missing GDPR Data Processing Agreement with Service Provider
A Slovenian company was fined €1,282 after failing to establish a formal Data Processing Agreement (DPA) with a third-party service provider handling employee personal data, violating GDPR Article 28(3). The root cause was a lack of governance oversight by the data controller's legal representative, who neglected to formalize the contractual relationship before data processing began. This matters because Article 28(3) is a mandatory legal safeguard — without a DPA, data subjects lose contractual protections over how their personal data is handled by processors. Even smaller fines signal regulatory intent to enforce third-party data governance rigorously, and repeat failures could attract much larger penalties.
Tactical Insight
Immediate actions
- Audit all existing third-party service providers to confirm valid, signed Data Processing Agreements are in place before any personal data is shared.
- Suspend or restrict personal data flows to any vendor lacking a compliant DPA until the agreement is executed.
Long-term improvements
- Maintain a formal Vendor/Processor Register that tracks DPA status, review dates, and data categories processed for every third-party relationship.
- Embed DPA execution as a mandatory gate in the vendor onboarding workflow so no personal data transfer can proceed without a signed agreement.
- Assign a designated Data Protection Officer or compliance role with ownership over periodic DPA reviews and renewals.
Awareness & governance measures
- Train legal representatives and procurement staff on GDPR Article 28 obligations so they understand the mandatory nature of DPAs.
- Implement an annual compliance check against all active data processor relationships to identify and remediate contractual gaps.