Slovenian Institution Fails to Identify Breach Victims or Honor Access Rights
A Slovenian public institution suffered a data breach and compounded the harm by failing to properly identify which individuals were affected and providing vague, non-committal responses to their GDPR Article 15 access requests. This violated multiple GDPR obligations — including transparency (Article 13), right of access (Article 15), security measures (Article 32), and breach notification to data subjects (Article 34). The case illustrates that a breach itself is only part of the problem; inadequate post-breach processes and poor data subject communication can independently constitute serious regulatory violations. Organizations must have pre-defined procedures for mapping affected individuals quickly and communicating with them clearly and promptly.
Tactical Insight
Immediate actions
- Establish a data breach response runbook that includes a step-by-step process for identifying all affected data subjects within 72 hours.
- Audit current access request (DSAR) workflows to ensure they produce explicit, unambiguous confirmations of data involvement rather than generic responses.
- Designate a responsible owner (e.g., DPO or Privacy Officer) to approve all breach-related communications to data subjects.
Long-term improvements
- Maintain a continuously updated data inventory and record of processing activities (RoPA) so affected individuals can be identified rapidly during any incident.
- Implement an access policy that clearly defines how data subject rights requests are handled, escalated, and documented in compliance with GDPR Article 15.
- Conduct annual tabletop exercises simulating data breach scenarios, including the identification of affected data subjects and drafting of Article 34 notifications.
Detection & compliance measures
- Deploy a case management system to track all DSARs and breach notifications with SLA timers to prevent missed deadlines.
- Schedule quarterly GDPR compliance reviews covering Articles 13, 15, 32, and 34 obligations to catch procedural gaps before regulators do.