[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2FYjnX3M-3Ghert4ZGlCL01Cp_MXFnLkr4CXsTk8A2Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"849ca913-ee47-4a14-87d5-bc47380955a9","spanish-dpa-fines-controller-200k-for-dpia-failure-and-security-gaps-that-enabled-data-breach","d47ab4b2-72be-4a4d-8238-ac519f96c453","Spanish DPA Fines Controller €200K for DPIA Failure and Security Gaps That Enabled Data Breach","The AEPD determined that internal security vulnerabilities — not merely the external attack itself — were the true cause of the breach, holding the controller accountable for failing to implement adequate protective measures. This case reinforces the principle that organisations cannot deflect GDPR liability by blaming threat actors when their own security posture is deficient. Critically, the controller also failed to conduct a mandatory Data Protection Impact Assessment (DPIA) under Article 35 GDPR before processing high-risk categories such as health data and data relating to minors. This dual failure — inadequate technical security and missing procedural safeguards — demonstrates how compliance and security must be treated as inseparable obligations. Organisations handling sensitive data must proactively assess risk before processing begins, not only after a breach occurs.","**Immediate actions:**\n- Conduct an urgent internal vulnerability assessment to identify and remediate security weaknesses across all systems handling personal data.\n- Initiate a Data Protection Impact Assessment (DPIA) for any existing processing activities involving high-risk data categories (health data, children's data) where one has not been completed.\n\n**Long-term improvements:**\n- Embed DPIA screening into the project lifecycle so that high-risk processing is never initiated without a completed and documented assessment.\n- Establish a formal security baseline aligned to GDPR Article 32 requirements, including encryption, access controls, and resilience testing for systems holding sensitive personal data.\n- Implement a continuous vulnerability management programme with regular penetration testing and patch cycles for all data-processing infrastructure.\n\n**Detection and governance measures:**\n- Deploy centralised logging and anomaly detection to identify suspicious access to personal data stores before a breach can escalate.\n- Assign clear data protection accountability roles (DPO, system owners) with documented responsibility for DPIA reviews and security control validation.\n- Schedule periodic GDPR compliance audits that cross-check technical security controls against processing records and risk assessments.",[12,13,14,15,16,17,18,19,20,21,22],"GDPR Article 32 – Security of processing","GDPR Article 35 – Data Protection Impact Assessment","GDPR Article 5(1)(f) – Integrity and confidentiality principle","NIST SP 800-53 RA-3 – Risk Assessment","NIST SP 800-53 SI-2 – Flaw Remediation","NIST SP 800-53 SC-28 – Protection of Information at Rest","CIS Control 7 – Continuous Vulnerability Management","CIS Control 3 – Data Protection","CIS Control 16 – Application Software Security","ISO\u002FIEC 27001:2022 Annex A 8.8 – Management of technical vulnerabilities","ENISA Guidelines on DPIA","published","2026-07-03T12:21:00.858839+00:00","2026-07-03T12:21:00.786+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00020-2025&diff=52053&oldid=52050","aepd-spain-ps-00020-2025-bd216f","AEPD (Spain) - PS-00020-2025",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"d09580d0-cd7a-4b68-9170-5fa41174a07d","2026-07-03","afternoon","ThreatNoir Afternoon Brief — July 3","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-03\u002Fthreatnoir-afternoon-brief-2026-07-03.mp3"]