[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgDq7fkKZdWnK2W3DAZAmcdDAcCIb47Rc-c9zUsNUi30":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"643ec26d-98e9-49dc-84b9-8fc66e6cab94","stolen-unencrypted-laptop-triggers-gdpr-fines-for-controller-and-processor","e0e0c212-a7f0-479f-9da6-b5362027a287","Stolen Unencrypted Laptop Triggers GDPR Fines for Controller and Processor","A work laptop stolen from a parked car exposed landowners' names, addresses, and ID numbers because neither the data controller nor the processor had implemented adequate endpoint security measures such as full-disk encryption. The root failure was a lack of proper risk assessment and technical safeguards for portable devices holding personal data — a foundational GDPR requirement under Articles 24, 25, and 32. This case illustrates that physical theft remains a significant data breach vector and that 'appropriate technical measures' explicitly includes encryption of mobile devices. The dual fines against both controller and processor highlight that GDPR accountability extends across the entire data processing chain, and processors cannot simply defer security responsibilities to controllers.","**Immediate actions:**\n- Enforce full-disk encryption (e.g., BitLocker, FileVault) on all laptops and portable devices that store or access personal data.\n- Audit all external\u002Fportable devices used by processors and contractors to verify baseline security controls are in place.\n\n**Long-term improvements:**\n- Embed device security requirements (encryption, remote wipe, screen lock) into Data Processing Agreements (DPAs) with all processors.\n- Conduct formal Data Protection Impact Assessments (DPIAs) for any processing involving portable devices or off-site data access.\n- Implement a Mobile Device Management (MDM) solution to enforce and monitor security policies across all endpoints centrally.\n\n**Detection & response measures:**\n- Enable remote wipe and geolocation capabilities on all company-issued laptops so lost or stolen devices can be neutralised immediately.\n- Establish a device loss\u002Ftheft response procedure with defined timelines for breach notification assessment under GDPR Article 33.",[12,13,14,15,16,17,18,19,20,21,22,23],"GDPR Article 24 (Responsibility of the controller)","GDPR Article 25 (Data protection by design and by default)","GDPR Article 28 (Processor obligations and DPAs)","GDPR Article 32 (Security of processing)","GDPR Article 33 (Notification of a personal data breach)","CIS Control 4 (Secure Configuration of Enterprise Assets)","CIS Control 10 (Malware Defenses \u002F Endpoint Protection)","NIST SP 800-111 (Guide to Storage Encryption Technologies for End User Devices)","NIST CSF PR.DS-1 (Data-at-rest protection)","NIST CSF PR.IP-1 (Baseline configuration)","ISO\u002FIEC 27001:2022 Annex A 8.1 (Endpoint device security)","ISO\u002FIEC 27001:2022 Annex A 7.9 (Security of assets off-premises)","published","2026-07-30T14:20:24.201281+00:00","2026-07-30T14:20:23.867+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.5.2025&diff=52560&oldid=0","uodo-poland-dkn-5131-5-2025-83b865","UODO (Poland) - DKN.5131.5.2025",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]