Back to all lessons
Awareness Lessons
4 months ago

Slovenian DPA Sanctions Controller for Breach Notification Failures and Inadequate Access Policy

A Slovenian public institution failed to implement an appropriate access control policy, leaving it unable to identify which individuals were affected by a data breach. Compounding the problem, the controller failed to properly respond to data subject access requests and did not provide clear, unambiguous communication about whether personal data had been compromised. These failures violated multiple GDPR articles — including Articles 13, 15, 17, 32, and 34 — covering transparency, data subject rights, security measures, and breach notification obligations. This case illustrates how weak access governance not only creates the conditions for a breach but also severely hampers an organization's ability to respond effectively and meet its legal obligations afterward.

Tactical Insight

Immediate actions

  • Conduct an urgent audit of all access control policies to ensure role-based permissions are documented and enforced.
  • Establish a formal process for responding to data subject access requests (DSARs) within GDPR's 30-day deadline, with clear templates for breach-related disclosures.
  • Identify and log all personal data assets so that breach impact assessments can be performed quickly and accurately.

Long-term improvements

  • Implement a Data Protection Management System (DPMS) that maps data flows, assigns data ownership, and tracks access rights continuously.
  • Develop and rehearse a breach response playbook that includes explicit steps for notifying affected data subjects per GDPR Article 34.
  • Integrate privacy-by-design principles into system procurement and development to reduce the risk of access policy gaps.

Detection & compliance measures

  • Deploy centralized logging and monitoring to detect unauthorized data access and support post-incident forensic investigations.
  • Schedule regular GDPR compliance audits, including mock DSAR exercises, to validate that response procedures are functional and staff are trained.
  • Assign a qualified Data Protection Officer (DPO) with authority to oversee access control reviews and breach notification decisions.