Back to all lessons
Awareness Lessons
3 weeks ago

Slovenian Institution Fails to Identify Breach Victims or Honor Access Rights

A Slovenian public institution suffered a data breach and compounded the harm by failing to properly identify which individuals were affected and providing vague, non-committal responses to their GDPR Article 15 access requests. This violated multiple GDPR obligations — including transparency (Article 13), right of access (Article 15), security measures (Article 32), and breach notification to data subjects (Article 34). The case illustrates that a breach itself is only part of the problem; inadequate post-breach processes and poor data subject communication can independently constitute serious regulatory violations. Organizations must have pre-defined procedures for mapping affected individuals quickly and communicating with them clearly and promptly.

Tactical Insight

Immediate actions

  • Establish a data breach response runbook that includes a step-by-step process for identifying all affected data subjects within 72 hours.
  • Audit current access request (DSAR) workflows to ensure they produce explicit, unambiguous confirmations of data involvement rather than generic responses.
  • Designate a responsible owner (e.g., DPO or Privacy Officer) to approve all breach-related communications to data subjects.

Long-term improvements

  • Maintain a continuously updated data inventory and record of processing activities (RoPA) so affected individuals can be identified rapidly during any incident.
  • Implement an access policy that clearly defines how data subject rights requests are handled, escalated, and documented in compliance with GDPR Article 15.
  • Conduct annual tabletop exercises simulating data breach scenarios, including the identification of affected data subjects and drafting of Article 34 notifications.

Detection & compliance measures

  • Deploy a case management system to track all DSARs and breach notifications with SLA timers to prevent missed deadlines.
  • Schedule quarterly GDPR compliance reviews covering Articles 13, 15, 32, and 34 obligations to catch procedural gaps before regulators do.