Back to all lessons
Awareness Lessons
3 months ago

Slovenian DPA Penalises Controller for Breach Response Failures and Poor Access Policy

The controller failed on two critical fronts: implementing an appropriate access policy that could have limited the breach's impact, and properly responding to data subjects' rights requests in the aftermath. Under GDPR, organisations are obligated not only to prevent breaches through sound access controls but also to transparently communicate with affected individuals when breaches do occur. Failing to confirm whether specific individuals' data was compromised directly undermines data subjects' rights to erasure and access. This case highlights that a data breach is not just a technical failure — it is also a test of an organisation's legal and procedural readiness to respond under the GDPR framework.

Tactical Insight

Immediate actions

  • Audit and enforce least-privilege access policies across all systems holding personal data.
  • Establish a documented breach notification workflow that includes individual data subject communication procedures.

Incident response improvements

  • Create a dedicated process for identifying and cataloguing which specific individuals are affected during any data breach investigation.
  • Train incident response teams to handle data subject access and erasure requests that arise as a direct result of a breach.
  • Assign a responsible owner (e.g., DPO) to track and document all data subject rights requests during and after an incident.

Long-term compliance measures

  • Conduct regular GDPR readiness assessments covering both preventive controls and breach response obligations.
  • Maintain comprehensive records of processing activities (RoPA) to enable rapid identification of affected data subjects in a breach scenario.
  • Integrate data subject rights request handling into your incident response plan and test it through tabletop exercises.