# Data Breaches — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/datalekken
> Sources are cited per item. Verify against the official texts before relying on them.

Security incidents involving unauthorized access to personal data

## Overview

## Legal Framework

The GDPR governs personal data breaches primarily through Articles 33 and 34. Article 33 requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. A later notification is permissible but must be justified with reasons for the delay. Information may be provided in phases where not all details are immediately available, as confirmed by Recital 86. Article 34 imposes a corresponding obligation to communicate the breach to affected data subjects when the breach is likely to result in a high risk to their rights and freedoms. Article 4 provides the foundational definitions, including the scope of "personal data," which determines what constitutes a breach in the first place. The 72-hour clock starts when the controller gains awareness — meaning when the controller has a reasonable degree of certainty that a security incident has occurred affecting personal data, not merely when an anomaly is first flagged.

## Key Developments

The *Zeehondenmail* case illustrates that breaches extend well beyond external cyberattacks. An employer was held accountable because its internal work processes allowed a colleague to access another employee's mailbox without authorization — the court found the employer's process design itself was at fault. This establishes that organizational failures in access management constitute reportable breaches. The GGD data leak litigation (WAMCA proceedings) demonstrates the severe civil liability exposure: claimants sought joint and several liability for all damages suffered, alongside court-ordered remediation of security deficiencies within a fixed timeframe. The RIVM vaccination data case confirms that even deletion requests involving special category data (Article 9) require stringent identity verification, and that mishandling such processes can itself constitute a breach. On the enforcement side, UODO fined the Mayor of Myślenice €1,790 under Article 33(1) for notification failures, and a Polish housing association €2,350 for insufficient breach notification compliance — signaling that even modest fines carry reputational and operational consequences, particularly in the public sector.

## Practical Guidance

- **Establish internal breach detection and escalation procedures** that feed into the 72-hour notification clock. The controller's awareness — not the IT team's initial detection — triggers the deadline. Ensure incident response protocols distinguish between preliminary investigation and confirmed awareness.

- **Document every decision point**, including the rationale for any delayed notification beyond 72 hours. Recital 86 permits phased reporting, but each phase must be substantiated. Maintain an internal breach register as required by Article 33(5).

- **Conduct risk assessments for each breach** to determine whether Article 34 communication to data subjects is triggered. The threshold is "high risk to rights and freedoms" — breaches involving special category data, financial data, or large-scale exposure will typically meet this standard.

- **Audit access controls and internal processes proactively.** The *Zeehondenmail* ruling confirms that preventable internal access failures are attributable to the controller. Shared mailbox configurations, delegated access, and insufficient segregation of duties all create breach exposure.

- **Prepare breach notification templates in advance** covering both Article 33 (authority) and Article 34 (data subject) requirements, including the mandatory content elements: nature of the breach, categories and approximate numbers of affected individuals and records, likely consequences, and mitigation measures taken or proposed.

## Legislation (full text of key provisions)

### Communication of a personal data breach to the data subject

*Source: GDPR, gdpr-art-34-en, 2016-04-27 — https://overview.legal/posts/90649*

### Infringements entailing a personal data breach

*Source: NIS2, nis2-art-35-en, 2022-12-14 — https://overview.legal/posts/96467*

### Notification of a personal data breach to the supervisory authority

*Source: GDPR, gdpr-art-33-en, 2016-04-27 — https://overview.legal/posts/90633*

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Recital 86 — data breach notification to data subjects

*Source: GDPR, gdpr-rec-86-en, 2016-04-27 — https://overview.legal/posts/91687*

The controller should communicate to the data subject a personal data breach, without undue delay, where that personal data breach is likely to result in a high risk to the rights and freedoms of the natural person in order to allow him or her to take the necessary precautions. The communication should describe the nature of the personal data breach as well as recommendations for the natural person concerned to mitigate potential adverse effects. Such communications to data subjects should be made as soon as reasonably feasible and in close cooperation with the supervisory authority, respecting guidance provided by it or by other relevant authorities such as law-enforcement authorities. For example, the need to mitigate an immediate risk of damage would call for prompt communication with data subjects whereas the need to implement appropriate measures against continuing or similar personal data breaches may justify more time for communication.

### Recital 85 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-85-en, 2016-04-27 — https://overview.legal/posts/91685*

A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred, the controller should notify the personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the controller is able to demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay.

### Recital 88 — personal data breach notification rules

*Source: GDPR, gdpr-rec-88-en, 2016-04-27 — https://overview.legal/posts/91691*

In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be given to the circumstances of that breach, including whether or not personal data had been protected by appropriate technical protection measures, effectively limiting the likelihood of identity fraud or other forms of misuse. Moreover, such rules and procedures should take into account the legitimate interests of law-enforcement authorities where early disclosure could unnecessarily hamper the investigation of the circumstances of a personal data breach.

### Recital 87 — personal data breach notification requirements

*Source: GDPR, gdpr-rec-87-en, 2016-04-27 — https://overview.legal/posts/91689*

It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

## Case law

### X - BA-6S/221/2019

*Source: Regional Administrative Court Bratislava, 2025-06-25 — https://overview.legal/posts/132105 — original: https://gdprhub.eu/index.php?title=X_-_BA-6S/221/2019*

Facts — Sociálna poisťovňa, the social insurance agency (the controller), processes applications for foreign invalidity pensions and forwards related documents to the social insurance institutions of other EU Member States. A data subject applied for a Danish invalidity pension. On 22 October 2018, the controller sent the data subject's sensitive personal data (including health data, personal identification number and a Danish personal identifier) to the Danish social insurance institution by ordinary (uninsured, untracked) second-class mail rather than by registered mail. The data subject could not confirm delivery and, in November 2018, filed a request with the Slovak DPA alleging that sending sensitive data by ordinary mail, without any proof of dispatch or protection against loss, violated their data protection rights. The controller resent the documents by the same method in December 2018. The DPA's first-instance decision (13 June 2019) found that the controller had violated Article 24(1) in conjunction with Article 32(1) and (2) GDPR, because sending sensitive personal data by ordinary rather than registered mail did not ensure a level of security appropriate to the risk. The DPA ordered the controller to use registered mail for such dispatches going forward and imposed a fine of €50,000. The controller's appeal was rejected, and the Slovak DPA president upheld the first-instance decision. The controller then brought an action before the Regional Administrative Court Bratislava, arguing among other things that: the parcel had in fact been delivered (as confirmed by the Danish institution by email), registered mail offers no greater protection against loss of confidentiality than ordinary mail, only one data subject was concerned and no damage had occurred and the decision's operative part improperly referred to the data of pension applicants generally, not just the individual data subject who had filed the complaint. Holding — The court did not rule on the substance of the security measures dispute, since it found the DPA's decision unreviewable on procedural grounds. First, the court held that the operative part of the DPA's decision was contradictory and imprecise. The administrative proceedings had been triggered by, and the evidence had concerned, an alleged violation of rights of one specific data subject (loss of their parcel). However, the decision extended the finding of violation to the controller's general practice of sending all pension applicants' data by ordinary mail. The court noted that a systemic pattern affecting other data subjects could, at most, be taken into account as an aggravating circumstance when setting the fine, but it could not itself form part of the sanctioned conduct in a proceeding limited to one individual's complaint. Second, the court found that the DPA had failed to properly assess evidence submitted by the controller showing that the parcel had actually been delivered to the Danish institution. The DPA only addressed this evidence for the first time in its written observations in the court proceedings, not in the administrative decision itself, even though the decision's entire reasoning rested on the (contested) premise that the parcel had been lost. Third, the court observed that the fine had been imposed under a provision of the national Data Protection Act that only permits fines for breaches of Articles 25 to 32 GDPR, whereas the DPA's decision had also relied on Article 24(1) GDPR, which is not covered by that provision. Because of these defects, the court annulled the DPA's decision and remanded the case for further proceedings, without addressing the parties' remaining arguments on the merits . The court instructed the DPA to first clearly establish the specific conduct underlying the alleged offence and then decide the case again, addressing all evidence submitted by the controller. The court awarded the controller full reimbursement of costs.

### Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21.

*Source: Court of Justice of the European Union, C-768/21, 2024-09-26 — https://overview.legal/posts/132245 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0768*

In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI) for declining to exercise corrective powers against Sparkasse X following a personal data breach complaint. The Court clarified the limits of supervisory authorities' discretion under GDPR Articles 57(1) and 58(2), holding that while authorities retain discretion in selecting corrective measures, they are legally obliged to exercise those powers when an infringement is established, and complainants have a right to an effective remedy under Article 77 even where no enforcement action was taken. No fine was imposed in this proceeding, as the ruling addressed the supervisory authority's enforcement obligations rather than penalizing a controller.

### Judgment of the Court (First Chamber) of 10 December 2020.#Land Nordrhein-Westfalen v D.-H. T. as liquidator of J & S Service UG.#Request for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Personal data – Regulation (EU) 2016/679 – Article 23 – Restrictions to the data subject’s rights – Significant financial interest – Enforcement of civil law claims – National legislation referring to the provisions of EU law – Tax data concerning a legal person –

*Source: Court of Justice of the European Union, C-620/19, 2020-12-10 — https://overview.legal/posts/132326 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0620*

In Case C-620/19, the Court of Justice of the European Union (First Chamber) addressed a preliminary ruling from the German Bundesverwaltungsgericht concerning whether Article 23(1)(e) and (j) of the GDPR permits national legislation restricting data subjects' rights to access tax data for the enforcement of civil law claims. The dispute arose between Land Nordrhein-Westfalen and D.-H. T., acting as insolvency administrator of J & S Service UG, regarding a request for the company's tax data. The Court found that because the GDPR does not apply to the processing of personal data concerning legal persons, it lacked jurisdiction to interpret Article 23 in this context, as the tax data at issue related to a legal entity rather than a natural person.

### Judgment of the Court (Third Chamber) of 20 June 2024.#JU and SO v Scalable Capital GmbH.#Request for a preliminary ruling from the Amtsgericht München.#References for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 82 – Right to compensation for damage caused by data processing that infringes that regulation – Concept of ‘non-material damage’ – Compensation of a punitive nature or purely in respect of damag

*Source: Court of Justice of the European Union, C-182/22, 2024-06-20 — https://overview.legal/posts/132254 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62022CJ0182*

In Joined Cases C-182/22 and C-189/22, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Amtsgericht München concerning the interpretation of Article 82 GDPR in proceedings brought by data subjects JU and SO against Scalable Capital GmbH following the theft of their personal data from the company's trading application. The core issue was whether Article 82 GDPR permits compensation for non-material damage that is minimal or symbolic, and whether such compensation can serve a punitive function. The Court held that Article 82 GDPR does not preclude the awarding of minimal compensation for non-material damage, such as distress following a personal data breach, provided the damage is genuine and actually arose from the infringement, but clarified that compensation under the GDPR must be purely reparative and cannot have a punitive character.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

### SG Nürnberg - S 5 SF 65/24 DS

*Source: Social Court Nuremberg, 2026-06-10 — https://overview.legal/posts/122874 — original: https://gdprhub.eu/index.php?title=SG_Nürnberg_-_S_5_SF_65/24_DS*

Facts — The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised "MOVEit Transfer," a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown "zero-day" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group "Clop." The hackers exploited this zero-day vulnerability to install a "web-shell" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as "3 / Orange" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding — The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing "state-of-the-art" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched.

### SO Warszawa - III C 904/23

*Source: Regional Court in Warsaw, 2026-02-16 — https://overview.legal/posts/53100 — original: https://gdprhub.eu/index.php?title=SO_Warszawa_-_III_C_904/23*

Facts — The Financial Ombudsman’s office (the controller) sent a letter containing the name, the address, and the case reference number of a customer (the data subject) to 28,366 public institutions and entities registered on an official government platform in February 2021. The data subject demanded compensation for the unauthorised disclosure of his personal data from the controller in November 2021. The controller refused to accept liability for the incident. The supervisory authority issued the controller a reprimand in September 2022 for disclosure of personal data in violation of Article 6(1) GDPR. The data subject brought a lawsuit for damages under Article 82 GDPR before the Regional Court in Warsaw in August 2023. The data subject stated that they had experienced severe stress and lost the sense of security and control over their data as a result of the unauthorised disclosure of the letter. The controller argued it was not at fault for the incident as it was caused by a temporary IT system failure that the controller could not have foreseen. Holding — The Regional Court in Warsaw held that the controller was undoubtedly liable for the unauthorised disclosure of the data subject’s personal data pursuant to Article 82 GDPR: the controller was an administrator for the government platform and had not taken adequate measures to secure the data. Second, the court held that the data subject had suffered non-material damage in connection with the aforementioned incident. It took into account that the data had been disclosed to numerous entities. In addition, the deterioration of the data subject’s mental state was confirmed by a witness. The court awarded the data subject PLN 40,000 in damages. It considered the data subject’s claim of PLN 50,000 to be excessive in light of established case law.

### CJEU - C‑755/21 P - Kočner v Europol

*Source: GDPRhub, 2024-03-05 — https://overview.legal/posts/122879 — original: https://gdprhub.eu/index.php?title=CJEU_-_C‑755/21_P_-_Kočner_v_Europol*

Facts — Following the murder of a Slovak journalist and his fiancée, Mr Ján Kuciak and Ms Martina Kušnírová, in Slovakia on 21 February 2018, the Slovak authorities (Národná kriminálna agentúra (National Crime Agency, Slovakia; ‘NAKA’)) conducted an extensive investigation. At the request of those authorities, the European Union Agency for Law Enforcement Cooperation (‘Europol’) extracted the data stored on two mobile telephones allegedly belonging to Mr Marian Kočner, the data subject, who was prosecuted as an accomplice to that murder for having ordered the killings, following the investigation. Europol sent its scientific reports to those authorities and delivered to them a hard disk containing the encrypted data it had extracted. In one of its reports, Europol stated that Mr Kočner had been detained on suspicion of a financial offence since 2018 and that his name was, inter alia, directly linked to the ‘so-called mafia lists’ and the ‘Panama Papers’. In May 2019, the Slovak press and international network of investigative journalists published a large amount of information relating to Mr Kočner from his mobile telephones, including transcripts of intimate communications exchanged between him and his girlfriend. The conversation was carried by means of encrypted messaging service. For the reasons stated above, Mr Kočner sent a complaint to Europol seeking compensation in the amount of €100,000 as a reparation for the non-material damage on the bases of Article 50(1) Regulation 2016/794. The sought compensation consisted of €50,000 for the unlawful disclosure of data subject's intimate conversation with his girlfriend and €50,000 for the inclusion of his name on the 'mafia list'. Europol and Slovak Republic contended that the arguments are unfounded as, firstly, Regulation 2016/794 (setting up the rules for the Europol) does not provide for such joint liability of Europol and the Member State. Secondly, Europol rejects any liability due to the absence of unlawful conduct on its part given that alleged harmful events occurred during storage of the national investigation file. As such, these circumstances do not constitute ‘unlawful data processing operations’ within the meaning of Article 50(1) Regulation 2016/794. Lastly, Europol stated that even if joint liability was applicable, the absence of any unlawful conduct on its part and of a causal link between such conduct and the damage suffered could not give rise to a liability. Holding — Firstly, the CJEU ruled that there is no need to establish additionally to which of these two entities - Europol or the Member State - that unlawful processing was attributable. In order for such joint and several liability to be incurred in the first stage, the individual concerned must show only that, in the course of cooperation between Europol and the Member State concerned, unlawful data processing that caused him or her to suffer damage has been carried out. Secondly, concerning specifically the leak of the 'so-called mafia list', the CJEU found that the data subject had failed to establish that the ‘mafia lists’ on which his name had allegedly been included had been drawn up and kept by Europol. The data subject's claim contradicted the evidence whereby it was apparent that the leaked Europol report containing Mr Kočner’s name on the ‘mafia list’ was subsequent to and, thus, unrelated to Slovak press publications where he was represented as ‘member of the mafia’. Thirdly, the CJEU rejected the Europol’s argument that it met its obligations and implemented appropriate technical and organizational measures to protect personal data against any form of unauthorized access. The Court observed that the data of such intimate nature bears out the need for its protection to be strictly ensured in cooperation with Member States under Regulation 2016/794. As an unauthorized access took place it constituted a sufficiently serious breach of a rule of EU law intended to confer rights on individuals. Fourthly, the Court held that European Union can incur non-contractual liability in the present case, as the result of publication of data subject’s intimate conversations. The leak of this information adversely affected his honour and professional reputation, and violated his rights to privacy, family life and respect for his communications guaranteed by Article 7 of the Charter of Fundamental Rights of the European Union. As a result, the CJEU held Europol and the Slovak Republic jointly and severally liable for the unlawful data processing which caused the data subject to suffer non-material damage. The Court stated that Europol has the possibility to refer the matter to its Management Board so that it can determine who has the ultimate responsibility for the compensation awarded to the data subject. However, this exclusively concerns the internal allocation of responsibilities between the two jointly liable controllers. The compensation attributed to the data subject for the inclusion of his name on the ‘mafia list’ by Europol was firstly set at €50,000. As this claim was dismissed, the Court only examined the damage regarding the compensation of €50,000 for disclosure of the data subject’s conversation with his girlfriend. The Court decided that the alleged damage resulted solely from the disclosure of transcripts of the conversation and no evidence established that any photographs have been disclosed. As a result, the CJEU granted Mr Kočner compensation in the amount of €2,000 as reparation for that damage.

### Judgment of the Court (Third Chamber) of 25 January 2024.#BL v MediaMarktSaturn Hagen-Iserlohn GmbH.#Request for a preliminary ruling from the Amtsgericht Hagen.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Interpretation of Articles 5, 24, 32 and 82 – Assessment of the validity of Article 82 – Inadmissibility of the request for an assessment of validity – Right to compensation for damage caused by

*Source: Court of Justice of the European Union, C-687/21, 2024-01-25 — https://overview.legal/posts/132272 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0687*

In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht Hagen in proceedings between data subject BL and MediaMarktSaturn Hagen-Iserlohn GmbH concerning alleged non-material damage from personal data transmitted to an unauthorized third party due to employee error. The Court held that a controller's infringement of GDPR security obligations through employee error can give rise to a right to compensation under Article 82, that the severity of the infringement may be relevant to assessing both the appropriateness of protective measures and the existence of damage, and that the concept of non-material damage should be interpreted broadly without requiring a minimum threshold of severity. No fine was imposed, as the ruling addresses interpretation of GDPR provisions rather than administrative penalties.

### Judgment of the Court (First Chamber) of 20 October 2022.#Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(b) and (e) – Principle of ‘purpose limitation’ – Principle of ‘storage limitation’ – Creation, from an existing database, of a datab

*Source: Court of Justice of the European Union, C-77/21, 2022-10-20 — https://overview.legal/posts/132306 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0077*

In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) concerning a personal data breach. The Court held that creating a new database from an existing one for testing and error-correction purposes constitutes further processing requiring compatibility assessment under the purpose limitation principle, and that the storage limitation principle applies such that data must be deleted once the testing purpose is fulfilled. No fine was imposed at the EU level, as the matter was remitted to the referring Hungarian court.

### VG Ansbach - 14 K 19.01274

*Source: VG Ansbach, 2021-09-22 — https://overview.legal/posts/158450 — original: https://gdprhub.eu/index.php?title=VG_Ansbach_-_14_K_19.01274*

Facts — In December 2018, the data subject filed with the DPA (the defendant in this case), a complaint under Article 77 GDPR against a lawyer who had represented the data subject in a traffic accident, before he terminated the mandate. In court proceedings after this termination, in which the lawyer's fee claim was at issue, the lawyer had submitted to the court a volume of documents containing extracts of all correspondence with the opposing insurance company, in which personal data and business secrets had not been blacked out. Since data subject had not released the lawyer from data protection and confidentiality, the data subject perceived this to be a breach of confidentiality. By letter dated 30 March 2016, the data subject contacted the lawyer regarding this breach. The data subject also complained to the Court about the lawyer's conduct, but this did not lead to any action undertaken by the Court. DPA acknowledged receipt of the complaint by letter dated 7 January 2019. In response to this complaint dated 31 May 2019, the DPA informed the data subject that it did not see any breach of data protection law in the conduct complained of and that there was therefore no reason for further supervisory measures pursuant to Article 58 GDPR. The lawyer was under no obligation to make the data subject's data unidentifiable when forwarding it to the court. According to the DPA, this processing was legitimised under Article 6(1)(f) GDPR since the pursuit of fee claims undoubtedly constitutes a legitimate interest of the lawyer. Moreover, the DPA held that, insofar as the personal data transferred were data belonging to special categories of data within the meaning of Article 9(1) GDPR (such as information on the consequences of the accident/injuries suffered by the data subject in the accident), the additional requirements of Article 9(2) GDPR were also met, as the transfer had been necessary for the assertion of legal claims. The data subject then brought the action to the Court, requesting her complaint to be accepted pursuant to Article 77 GDPR. Holding — The Court dismissed the action and found that the data subject's complaint of 29 December 2018 did not constitute a complaint under Article 77 GDPR, but a "submission" within the meaning of Article 28(4) of Directive 95/46/EC. In the present case the data subject claimed that a data protection breach occured in March 2016. As the GDPR has only been applicable since 25 May 2018, the conduct of the lawyer could therefore not have infringed the GDPR, as it was not yet applicable at that time. There was no transitional provision in German law stipulating that the GDPR also applied to facts before the above-mentioned date. The Court noted that the entry-into-force of the GDPR according to Article 99 GDPR represents a clear break between the old and the new law. Since the German legislator - unlike the Austrian legislator, for example - did not enact a transitional provision which, under certain circumstances, ordered the application of the new law also to breaches of data protection provisions committed before its entry into force, breaches committed before that date are fully subject to the old law.

### Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether

*Source: Court of Justice of the European Union, C-507/23, 2024-10-04 — https://overview.legal/posts/132162 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0507*

The Court of Justice of the European Union issued a preliminary ruling on a reference from the Latvian Supreme Court in Case C-507/23, involving an individual ("A") and the Patērētāju tiesību aizsardzības centrs (Consumer Rights Protection Centre, Latvia) regarding compensation for non-material damage allegedly suffered from unlawful processing of personal data under Article 82(1) GDPR. The Court addressed whether apologies can constitute compensation for non-material damage and whether the controller's attitude and motivation may be considered in assessing the form and level of compensation. No fine was imposed, as the ruling clarifies interpretive questions of EU law for the referring national court.

## Guidance

### Guidelines 9/2022 on personal data breach notification under GDPR

*Source: EDPB, edpb-guidelines-on-personal-data-breach-notification-under-gdpr, 2023-04-04 — https://overview.legal/posts/38058 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-92022-on-personal-data-breach-notification-under-gdpr_en*

The EDPB adopted Guidelines 9/2022 (Version 2.0, 28 March 2023) to update and replace the prior WP250 guidance on personal data breach notification under Articles 33 and 34 of the GDPR. The guidelines address the definition and types of personal data breaches, controller and processor notification obligations, the concept of a controller becoming "aware" of a breach, cross-border and non-EU establishment breach scenarios, and the conditions under which notification to supervisory authorities and data subjects is or is not required.

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Guidelines on Personal data breach notification under Regulation 2016/679, WP250 rev.01

*Source: EDPB, guidelines-on-personal-data-breach-notification-under-regulation-2016679-wp250-en, 2018-05-25 — https://overview.legal/posts/126319 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-personal-data-breach-notification-under-regulation-2016679-wp250_en*

Уведомления относно нарушение на сигурността на личните данни Насока 25 May 2018 Уведомления относно нарушение на сигурността на личните данни Related documents Всички

### Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)

*Source: EDPB, opinion-142019-on-the-draft-standard-contractual-clauses-en, 2019-07-12 — https://overview.legal/posts/126212 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142019-on-the-draft-standard-contractual-clauses_en*

Adopted 1 Opinion 14/2019 on the draft Standard Contractual Clauses sub mitted by the DK SA (Article 28( 8 ) GDPR) Adopted on 9 July 2019 Adopted 2 1 CONTENTS 2 Summary of the Facts ................................ ................................ ................................ .................... 4 3 Assessment ................................ ................................ ................................ ................................ .... 5 3.1 General reasoning of the Board…

### EDPB Leaflet

*Source: EDPB, edpb-leaflet-en, 2019-03-28 — https://overview.legal/posts/126228 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-leaflet_en*

edpb.europa.eu Editor: Secretariat of the European Data Protection Board, Rue Montoyer 30, 1047 Brussels. GDPR and your rights Data protection, a fundamental right for every EU data subject AI AI A new level of cooperation between European regulators The European Data Protection Board (EDPB), a new independent EU body, brings together all supervisory authorities in the EEA, as well as the European Data Protection Supervisor. The EDPB contributes to the consistent application of the GDPR by: •…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

## Enforcement decisions

### UODO (Poland) - DKN.5131.7.2022

*Source: UODO (Poland), 2026-04-13 — https://overview.legal/posts/53109 — original: https://gdprhub.eu/index.php?title=UODO_(Poland)_-_DKN.5131.7.2022*

Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone application between July 2020 and March 2021 to send pictures of customer contracts containing the personal data of individuals residing at addresses visited during door-to-door sales (the data subjects). The controller had not authorised this practice, and former employees of the sub-processor could still access the personal data through the app. The controller identified the use of the app as a data breach and notified the supervisory authority about it in April 2021. The DPA initiated administrative proceedings in March 2022. Holding — First, the DPA held that the controller had violated the principles of integrity and confidentiality enshrined in Article 5(1)(f) and the principle of accountability laid down in Article 5(2) GDPR. It had also violated Articles 24(1), 25(1), 28(1), 32(1) and 32(2) GDPR, which specify these principles. The DPA issued the controller a reprimand. The DPA found the controller had failed to implement appropriate technical and organisational measures itself and also failed to properly verify whether the (sub-)processors had provided sufficient guarantees that they had implemented such measures. The data protection agreements required in Article 28(1) GDPR were very general in nature, and none of the parties in the chain of contracts had conducted a risk analysis to select appropriate security measures. In addition, the controller had not continuously monitored the processing activities. Second, the DPA held that the two processor and the sub-processor had violated Articles 32(1) and 32(2) GDPR read in conjunction with Article 28(4) GDPR. They had all failed to implement appropriate technical and organisational measures to ensure the security of personal data processing. The sub-processor was largely held responsible for the data breach – it had started using the app to process customers’ personal data without authorisation from the controller or the processors. Furthermore, the DPA pointed out the sub-processor should have verified whether the application would allow access to the personal data through it even after the termination of the employment relationship. The DPA reprimanded the processors and fined the sub-processor €2,415.

### AEPD sanctions 23andMe for security failures in credential-stuffing breach

*Source: AEPD (Spain), 2025-10-10 — https://overview.legal/posts/158429 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00140-2025*

Facts — 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October. Holding — The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union. First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals. The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR.

### Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2021-06-30 — https://overview.legal/posts/46884 — original: https://www.enforcementtracker.com/ETid-769*

The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal education. The controller had not immediately informed the DPA and the data subjects about a personal data breach. Several folders containing personal data had been stolen from the controller in early 2020. These included the names, addresses and telephone numbers, and in 3 to 4 cases also the PESEL numbers (Polish identificatio

### Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2020-12-28 — https://overview.legal/posts/46616 — original: https://www.enforcementtracker.com/ETid-501*

The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a notification from a third party about a personal data breach involving an insurance agent acting as a processing agent for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. who sent an insurance policy to an unauthorized addressee by email. The document contained personal data concerning, among others, surnames, first name

### ANSPDCP (Romania) - Fine against Homelux SRL

*Source: ANSPDCP (Romania), 2026-08-11 — https://overview.legal/posts/187378 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Homelux_SRL*

Facts — HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. The website subsequently suffered a cyberattack affecting the security of the personal data processed through it. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, the security of personal data processed by the controller, including names, surnames, addresses, email addresses and passwords, was compromised. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. Holding — First, the DPA found that the controller infringed Article 32(1)(d) and 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. The DPA considered these shortcomings insufficient to ensure a level of security appropriate to the risk. It also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation and assessment of its IT systems and subsequent modifications. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts and limiting each user to only the access rights necessary for their role according to the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506/2004 on its website.

### ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026

*Source: ANSPDCP (Romania), 2026-07-29 — https://overview.legal/posts/144034 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Orange_Romania_SA_of_July_17,_2026*

Facts — The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its mobile application. A customer (the data subject) of the controller was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding — First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of RON 104,780 (€20,000). Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 419,120 (€80,000). In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing.

### AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data

*Source: AEPD (Spain), 2026-07-16 — https://overview.legal/posts/53655 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00020-2025*

Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first estimated that 25,000 persons were affected. It later stated that the incident had affected around 40,000 persons, including 75 minors. The incident affected confidentiality, availability and integrity. The attacker encrypted systems and exfiltrated between 3.5 and 4 TB of information from the document management server. The affected data included identification and contact data, ID numbers, dates of birth, financial and insurance data, bank account numbers, health data, employee data and access credentials. The controller also processed data relating to minors in accident claims. A data subject complained to the DPA after being informed that their personal data had been exposed. The data subject was concerned about identity theft and requested additional information from the controller. During the investigation, the DPA found that the controller had known that its IT systems faced an extreme cybercrime risk before the breach. The forensic report could not determine the initial entry point because the servers had been encrypted, but it showed that attackers could move laterally through the infrastructure, obtain privileged access, install tools, exfiltrate data and encrypt systems. The controller had carried out a risk analysis in 2019, but this document concluded that no DPIA was necessary. After the breach, a later analysis found that a DPIA was necessary for treatments involving health data and minors. The controller did not prove that it had carried out the required DPIA. Holding — The DPA held that the controller violated Article 5(1)(f) GDPR. It considered that the controller had failed to ensure the integrity and confidentiality of the personal data under its responsibility. The DPA emphasised that the principle in Article 5(1)(f) GDPR is not limited to the existence of isolated security measures. Rather, the controller must implement adequate technical and organisational measures capable of ensuring that personal data is protected against unauthorised or unlawful processing, loss, destruction or damage. The DPA rejected the controller’s argument that the attack was an external criminal act that could not be attributed to it. The DPA found that the controller was aware of an extreme cyber risk and that its internal vulnerabilities and security posture allowed the attackers to move through the systems, access personal data and encrypt files. The DPA therefore considered that the controller’s measures were clearly insufficient. The DPA also held that the controller violated Article 35 GDPR. The controller processed high-risk categories of data, including health data and data concerning minors. In these circumstances, it should have carried out a DPIA before the processing. The DPA found that the controller’s 2019 risk analysis wrongly concluded that no high risk existed, while its later documentation acknowledged that a DPIA was necessary. The DPA proposed a fine of €150,000 for the infringement of Article 5(1)(f) GDPR and €100,000 for the infringement of Article 35 GDPR, totalling €250,000. The controller paid voluntarily without acknowledging liability, obtaining a 20% reduction under Spanish Administrative Law (39/2015). The final payable amount was therefore €200,000. The DPA also ordered the controller, under Article 58(2)(d) GDPR, to prove within three months from the enforceability of the decision that it had carried out the mandatory DPIA required under Article 35 GDPR.

### VDAI (Lithuania) - 3R-1143

*Source: VDAI (Lithuania), 2026-06-19 — https://overview.legal/posts/53896 — original: https://gdprhub.eu/index.php?title=VDAI_(Lithuania)_-_3R-1143*

Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other personal data of patients (the data subjects). The first breach potentially concerned 63 data subjects, whereas the latter breach affected approximately 10,000 employees and 383,000 data subjects. The DPA initiated two separate investigations against the controllers in September 2024 and November 2025 respectively and later combined the cases. Holding — The DPA imposed a fine of €450,000 on the first controller it investigated as this company was also the legal successor of the other controller. It held that the controllers had failed to implement appropriate technical and organisational measures to ensure the security of processing and compliance with the principles of integrity and confidentiality. The controller had violated Articles 5(1)(f), 24(1), and 32(1)(b) GDPR. When assessing the GDPR infringements, the DPA took into account that the controllers processed sensitive categories of personal data. The DPA held the controllers lacked adequate security measures for protecting against unauthorised access to an IT system, such as access control and authentication. For instance, passwords used by employees did not reach a certain level of complexity, and multi-factor authentication was not used.

## Recent developments

### ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

*Source: GDPRhub, 2026-08-21 — https://overview.legal/posts/291402 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL*

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their fi

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### DPC (Ireland) - IN-19-9-4

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291263 — original: https://gdprhub.eu/index.php?title=DPC_(Ireland)_-_IN-19-9-4*

The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR.The DPA fined the HSE €300,000 for inadequate security measures which enabled a ransomware attack affecting health data of 84,000 people, alongside violations of Articles 28, 30 and 34 GDPR. English Summary. English Summary On 8 October 2019, the DPA initiated an own-volition inquiry to determine whether the

### EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

*Source: European Data Protection Board, 2026-06-10 — https://overview.legal/posts/53059 — original: https://www.edpb.europa.eu/news/edpb-meets-with-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification-template_en*

Brussels, 10 June – During its latest plenary, the EDPB met with Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection. In addition, the Board has adopted a common data breach notification template.The Board held a meeting with Commissioner McGrath, engaging in a fruitful discussion about common priorities and ongoing work on areas of mutual interest.The Digital Omnibus was among the key topics that shaped the discussion. The Board reiterated that, while s

### The Italian SA fined Poste Vita for data breach

*Source: European Data Protection Board, 2026-06-04 — https://overview.legal/posts/53061 — original: https://www.edpb.europa.eu/news/the-italian-sa-fined-poste-vita-for-data-breach_en*

Background informationDate of final decision: 10 July 2025National caseController: Poste Vita s.p.a.Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 33 (Notification of a personal data breach to the supervisory authority)Decision: Administrative fineKey words: Administrative fine, Clients, Data security, Insurance, Personal data breachSummary of the DecisionOrigin of the case The investigation was initiated following a complaint from an insurance compan

## Literature

### European Union ∙ EDPB Adopts updated Guidelines on Personal Data Breach Notification under GDPR: The End of the One-Stop-Shop Reporting Mechanism for Non-EU Establishments

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132622 — original: https://doi.org/10.21552/edpl/2022/4/11*

### GDPR and NIS 2 Reporting Duties in Personal-Data Breaches:

*Source: European Data Protection Law Review, 2026-01-01 — https://overview.legal/posts/132466 — original: https://doi.org/10.21552/edpl/2025/4/9*

### Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit?

*Source: European Data Protection Law Review, 2022-01-01 — https://overview.legal/posts/132504 — original: https://doi.org/10.21552/edpl/2022/4/8*

### IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION

*Source: Pravo ta nauki, 2018-12-30 — https://overview.legal/posts/132472 — original: https://doi.org/10.66556/2522-4549.1519.koshovyi-b*

The article examines the impact of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), which entered into force on 25 May 2018, on Ukrainian personal data protection legislation. The main novelties of GDPR are analyzed, including the principle of accountability, the right to erasure (right to be

### General Data Protection Regulation (GDPR) and Data Breaches: What You Should Know

*Source: Aesthetic Surgery Journal, 2018-10-29 — https://overview.legal/posts/132421 — original: https://doi.org/10.1093/asj/sjy296*

## Tools

### Meldloket datalekken Autoriteit Persoonsgegevens

*Source: Autoriteit Persoonsgegevens, 2026-07-04 — https://overview.legal/posts/53807 — original: https://datalekken.autoriteitpersoonsgegevens.nl/*

Het officiële loket van de Autoriteit Persoonsgegevens voor het melden van datalekken op grond van artikel 33 AVG. Verwerkingsverantwoordelijken melden hier binnen 72 uur een inbreuk in verband met persoonsgegevens, en kunnen meldingen aanvullen of intrekken.

### EDPB Data Protection Guide for Small Business

*Source: EDPB, 2026-07-04 — https://overview.legal/posts/53804 — original: https://www.edpb.europa.eu/sme-data-protection-guide/home_en*

Interactive guide by the European Data Protection Board that walks SMEs through GDPR compliance: lawful bases, individuals' rights, security of processing, data breach response, and international transfers — with practical examples and checklists.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/datalekken · 2026-08-22
