IP (Slovenia) - 0612-91/2025/40

From GDPRhub
IP - 0612-91/2025/40
Authority: IP (Slovenia)
Jurisdiction: Slovenia
Relevant Law: Article 13 GDPR
Article 15 GDPR
Article 17 GDPR
Article 32 GDPR
Article 34 GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided: 04.03.2026
Published:
Fine: n/a
Parties: n/a
National Case Number/Name: 0612-91/2025/40
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Slovenian
SL
Original Source: IP (in SL)
Initial Contributor: dt

The DPA ordered a controller to take measures to identify which data subjects were affected by a data breach and to properly respond to their access requests by explicitly informing them whether they were affected by the data breach.

English Summary

Facts

A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website. The DPA carried out an inspection at the controller’s premises.

In parallel, the controller shared on its website and with the media a press release with the aim of informing data subjects of the data breach.

Subsequently, the controller received several access requests under Article 15 GDPR from individuals requesting information, among other things, on whether the data breach affected their personal data.

To these requests the controller generally replied that the matter was under investigation and that the breach affected a unified registry of entities containing data subjects listed in various databases within the scope of the Slovenian Ministry of Agriculture.

Holding

The DPA found that the controller failed to implement an appropriate access policy in violation of Article 32 GDPR.

At the same time, the DPA held that the controller failed to respond appropriately to the data subjects’ access requests under Article 15 in relation to their personal data having been affected by the data breach since the response of the controller was not specific, explicit and unambiguous.

In addition, the DPA considered the response provided by the controller as breaching Article 34 GDPR (i.e. communication of a personal data breach to the data subject) and Article 13 GDPR (i.e. information to be provided where personal data are collected from the data subject).

Therefore, the DPA held that the controller must implement an appropriate access policy and additional measures in relation to the data subjects who addressed access requests in order to determine if the data breach affected them while documenting these measures in accordance with Article 32 GDPR.

Finally, the DPA ordered the controller to respond to erasure requests in accordance with Article 17 GDPR.

Comment

This is a partial decision in which the DPA issued a decision only on certain parts of the case. The DPA first ordered the controller to take measures to identify the data subjects and then implement technical and organisational measures to obtain information regarding whether the data subjects’ data were affected by the data breach. After implementing these measures and if the controller does not meet the requirements of Article 34 GDPR and Article 15 GDPR, the DPA shall issue a supplementary decision ordering the controller to take measures to comply with Article 15 GDPR and Article 34 GDPR.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the original. Please refer to the original for more details.

Number: 0612-91/2025/40
Date: 4. 3. 2026

The Information Commissioner (hereinafter referred to as the IP) is issued by the State Supervisor for Personal Data Protection on the basis of Articles 2 and 8 of the Information Commissioner Act (Official Gazette of the Republic of Slovenia, No. 113/05 and 51/07 - ZustS-A, hereinafter referred to as: ZInfP), Articles 29, 36 and 55 of the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163/22 and 40/25-ZInfV-1, hereinafter referred to as: ZVOP-2), the fifth paragraph of Article 29 and the first paragraph of Article 32 of the Inspection Act (Official Gazette of the Republic of Slovenia, No. 43/07 - UPB1 and 40/14, hereinafter referred to as: ZIN) and the second paragraph of Article 58 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: the General Regulation), in the matter of inspection of the implementation of the provisions of the General Regulation and ZVOP-2 at the obliged entity: … (hereinafter: the obliged entity), ex officio the following 

PARTIAL DECISION

I. The obliged entity must, in relation to the implementation of the provisions of the General Regulation, establish and adopt a written internal act on the regular review of all access rights to the obliged entity's information systems, which must include: a) a clearly defined procedure for the regular review of the access rights of all individual users, which must include at least the designation of the person responsible for carrying out the reviews, the determination of the minimum frequency of reviews, the method of verifying the eligibility of the granted rights in relation to the user's work tasks (or in relation to the purpose for which the access rights were granted), the method of documenting the review carried out and the procedure for eliminating identified non-compliances and b) a clearly defined procedure for regular review of access rights of all application users, which must include at least the determination of the person responsible for carrying out the reviews, the determination of the minimum frequency of reviews, the method of verifying the eligibility of the rights granted with regard to the purpose of establishing the application user, the method of documenting the review carried out and the procedure for eliminating identified non-compliances.

II. The liable party must, with regard to the requests of individuals: …, In relation to the implementation of the provisions of Articles 15 and 34 of the General Regulation and Article 13 of the ZVOP-2, the liable party must implement additional technical and organisational measures in order to establish whether their personal data were actually affected in a security breach in relation to the individuals: …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, …, who have addressed an explicit request to it for confirmation of whether their personal data were affected in a security breach and in respect of whom there is no justified doubt as to their identity, and must also properly document these measures in accordance with the fifth paragraph of Article 33 of the General Regulation, whereby the liable party must implement at least the following measures:
a) examine all log records or other technical/application/base records at the disposal of the liable party in connection with table … in order to establish the fact whether the individual was registered in the table …;
b) request … to examine all diary records or other technical/application/base records held by … in connection with table … (which is maintained by … and whose replication creates table …) in order to establish the fact whether the individual was entered in table … on or before that date and to forward such data and findings to the liable party and to take the data thus obtained into account in establishing the fact whether the individual was entered in table … on …;
c) examine all documentation relating to the individual held by the liable party in order to establish the fact whether the individual was entered in table … on …;
d) request … to examine all documentation relating to the individual in its possession …, with the aim of establishing the fact whether the individual was entered in table … on or before that date, and to forward such information and findings to the liable party and to take the data thus obtained into account in establishing the fact whether the individual was entered in table … on or before that date;
e) request … to address a request to …, in which it should request information from the latter on whether … … transmitted the individual’s data from … on or before that date, in connection with the integration on the basis of which … the individual’s data obtained from … is entered in table …, and to forward such information to the liable party and to take the data thus obtained into account in establishing the fact whether the individual was entered in table … on or before that date.

IV. The responsible party must decide on the request … for the deletion of personal data (in accordance with Article 17 of the General Regulation) in such a way that:
(i) it grants the request and makes an official note of the response to the individual or
(ii) it does not grant the request and issues a decision that, in addition to the elements specified by the law governing general administrative procedure, also contains the elements specified by the ZVOP-2. The decision must include in the legal instruction the right to appeal to the supervisory authority within 15 days of the service of the decision in the case, pursuant to the provisions of point f) of the first paragraph of Article 15 of the General Regulation.

After establishing that there is no justified doubt about the identity of …, the responsible party must decide on the request for … to delete personal data (in accordance with Article 17 of the General Regulation) in such a way that:

(i) it grants the request and makes an official note of the response to the individual or

(ii) it does not grant the request and issues a decision that, in addition to the elements specified by the law governing general administrative procedure, also contains the elements specified by the ZVOP-2. The decision must state in the legal instruction the right to appeal to the supervisory authority within 15 days of the service of the decision in the case, pursuant to the provisions of point f) of the first paragraph of Article 15 of the General Regulation.

V. The measure referred to in point I of the operative part of this decision must be implemented by the responsible party within 45 (forty-five) days of receipt of this decision.

VI. The measure referred to in point II of the operative part of this decision must be implemented by the responsible party within 5 days of receipt of this decision.

VII. The measure referred to in point III of the operative part of this decision must be implemented by the liable party within 40 (forty) days of receipt of this decision.

VIII. The measure referred to in point IV of the operative part of this decision must be implemented by the liable party within 40 (forty) days of receipt of this decision.

IX. The liable party must notify the IP in writing of the measures referred to in points I, II, III and IV of the operative part of this decision within 5 (five) days of implementation and submit evidence. 

X. No special costs were incurred in this procedure. 

Explanation

I. Explanations of the liable party

1. On …, the liable party submitted a preliminary notification of a personal data breach to the IP, stating in it that a personal data breach had occurred in the application on the website ... and ..., where technical measures had not been taken to prevent ... (hereinafter: security breach). On …, the liable party submitted a final official notification of a personal data breach (hereinafter: breach notification).
On … the taxpayer submitted a response to the summons and a supplement to the final report, the taxpayer's document number: … (hereinafter: the response to the summons dated …). 
On … the taxpayer submitted a document with the subject "…", the taxpayer's document number: … (hereinafter: the taxpayer's letter dated …). 
On … the IP conducted an inspection at the taxpayer's premises and drew up a report on the inspection dated …, document number: … (hereinafter: the report dated …). 
On … the taxpayer submitted the log records of the web server … for the period from … to … (hereinafter: the log records of the web server …). 
On … the taxpayer submitted a response to the summons to provide a written explanation, documentation and statement, the taxpayer's document number: … (hereinafter: the response to the summons dated …). 
On … the taxpayer submitted comments to the report, the taxpayer's document number: … (hereinafter: the comments to the report dated …). 
On … the taxpayer submitted explanations to the summons IP no. …, the liable party’s document number … (hereinafter: the response of …). 
On …, the liable party submitted a written response to the telephone conversation dated …, the liable party’s document number … (hereinafter: the response to the telephone conversation). 
On …, the liable party submitted documentation (printouts of all requests and questions from individuals), the liable party’s document number … (hereinafter: the printout of requests from individuals dated …). 
On …, the liable party submitted written explanations, a statement and documentation, the liable party’s document number … (hereinafter: the response of …). 
On …, the liable party submitted a document with the subject “…”, the liable party’s document number … (hereinafter: the response to the findings). 

In the documents submitted, the liable party provided written explanations and statements, which the supervisor summarizes below, whereby the supervisor summarizes only the statements in connection with the issue of checking the status of access rights and the issue of informing individuals or ensuring the rights of individuals.

Regarding the verification of the status of access rights 

2. In the notification of the violation, under the heading "DESCRIPTION OF THE VIOLATION", the liable party stated: "..., which should not be accessible to the user ..., they obtained personal data of ... natural persons (name, surname, address, date of birth, tax number and EMŠO), which are kept in ... on ... ... was taken from the user ...."

3. From point 14 of the minutes of ... (taking into account the comments on the minutes of ...) it follows that ... said: "that the application on the website ... is intended for viewing the register .... User ..., which is used to access the ... server. Given the purpose of the application, the user ... should not have approved access rights to personal data. Nevertheless, the user ... was granted rights to view the table ... and .... Based on the logs, it is not possible to determine who granted these rights to the user ... and when. The logs are stored only for the period from ... to ... and from ... to today. During this time, there were no interferences with the rights of this user. ”

4. In the response to the summons dated …, the liable party wrote: “….” At the same time, the liable party wrote: “….” In the same response to the summons, the liable party, when asked whether the liable party had set rules regarding the review of user rights (including the rights of service users) in its internal policies (e.g. information security policy), replied: “….”

5. In the response dated …, the liable party wrote regarding the treatment of user rights: “….”

6. In the response dated …, the liable party, when asked by the IP to refer to a provision in internal acts relating to the regular review of access rights, stated: “….”

7. In the response to the briefing on the findings dated …, the liable party repeated the statements given in the response dated … regarding the provisions in … and ….

Regarding the notification of individuals and requests from individuals for additional information about the security breach or requests from individuals pursuant to Article 15 of the General Regulation

8. In response to the summons dated …, the liable party stated that, for the purpose of informing individuals pursuant to Article 33 of the General Regulation, it prepared a press release, which the liable party forwarded to the media and which is available on the website “…”. The State Supervisor notes that this is a website entitled … (hereinafter: the press release), which states: 
”….

… immediately fixed the vulnerability, which prevented further access to the data. Current operations were not disrupted, nor were there any financial demands related to unauthorized access.

Individuals are advised not to share additional personal data by phone or email unless they are 100% sure who they are talking to. If they detect an attempt at such abuse, they should immediately notify the police.

… immediately notified the competent group … as the competent group for responding to … and the information officer of the unauthorized access and filed a report with the police.

Individuals who recognize themselves in these databases can contact the email address … for additional information 

9. The liable party stated in its response of …: 
“As already explained during the inspection procedure, we notified the individuals immediately after the incident,
i.e. on …, with a public notice, which we have already informed you of in letter no. ... dated ..., informed:
- about the incident itself (what and when it happened, when the event was detected and what type of personal data was disclosed),
- about the measures taken in relation to the disputed event,
- about the recommended measures for individuals who could be identified in the databases that were the subject of the attack (a call to be careful when further handling their own personal data and not to transmit any additional personal data by phone or e-mail if the individual is not completely sure of the identity of the person being contacted, and in the event of a suspected attempt to abuse, to immediately notify the Police, and also
- about the contact details of the authorized person for any additional clarifications, available at the e-mail address ....
In addition to the public notification to individuals of the personal data breach in accordance with point c) of paragraph 3 of Article 34 of the General Regulation (since individually informing all ... natural persons would undoubtedly require a disproportionate effort, (especially at a time when the priority was to take appropriate action to ensure the protection of personal data and adopt all necessary organizational and technical measures), we also provided individual responses to all individuals who contacted us with a question about whether their personal data was included among the personal data that was the subject of an attack, with all the information we had at our disposal at the time of the response. If any additional findings are made during the procedure, we will of course provide these to the individuals in a timely manner if necessary. 

10. The liable party stated the following regarding the available information/established facts regarding which individuals were affected by the security breach:
- in the breach notification it stated: 
• “… …“
• “…, which should not be accessible to the user …, obtained personal data of … natural persons (name, surname, address, date of birth, tax number and EMŠO), which are kept in … on ….”
• “Based on the queries used in …, where they systematically went from the first to the last record in steps …, they obtained all records from ….
The number … is the number of records in … on … at approximately …. (of which … persons are already deceased).”

- the following statements emerge from the minutes of …:
• “…...”
• “In response to the question of the state supervisor, can the liable party confirm that ….”
• “In response to the question of the state supervisor, could the liable party … reconstruct the content of … on ….”

- in the comments to the minutes of …, the liable party provided the following explanation regarding the supervisor’s findings in point 8 of the minutes of … (regarding the number of affected individuals):
• “….”
- in response to the summons of …, the liable party stated: 
”….”

11. In response to the IP’s question in the summons for a written explanation, documentation and statement of …, summons number 0612-91/2025/29 in point 3, the liable party stated in point 3 of the Response of …: “….”

12. In response to the briefing on the findings of …, the liable party provided its understanding of the right of access under Article 15 of the General Regulation, especially in connection with the definition of the term "user", as it is supposed to follow from Article 4 of the General Regulation. The liable party stated: "The liable party did not reasonably treat the applications received as requests from individuals under Article 15 of the General Data Protection Regulation (GDPR). Article 15 of the General Regulation refers exclusively to the rights of an individual to access his or her own personal data and to information about whether and to whom such data have been disclosed. In this regard, it is necessary to proceed from the definition of the term user in Article 4(9) of the GDPR, which stipulates that a user is a person or body to whom a controller or processor discloses personal data. The essential element of the definition is the disclosure of data, which, according to the established interpretation, covers a conscious, intentional and lawful act of the controller or processor. In cases of unlawful access to personal data, such as hacking into information systems or data theft, disclosure within the meaning of Article 4(9) of the GDPR does not occur. An unlawful data acquirer does not obtain personal data on the basis of an act of the controller or processor, but through his own unlawful conduct. Such an event therefore does not constitute a disclosure of data, but a personal data breach within the meaning of Article 4(12) of the GDPR. The General Regulation clearly distinguishes between disclosure as an act of the controller and unauthorised access as an unlawful act of a third party, due to which such an entity cannot acquire the legal status of a user. Legally speaking, it is a third party that carries out unlawful processing of personal data, which excludes any legitimate position within the controller's system or within the data flows defined in the record of processing activities. Unlawful access or disclosure as a result of a breach of confidentiality within the meaning of Article 4(12) of the GDPR is the result of a security vulnerability, not intentional or lawful processing of data by the controller or processor. "According to the obligated party, this also follows from the Guidelines on personal data breaches of the EDPB (European Data Protection Board), formerly WP29. According to the liable party, this interpretation is also followed by the Information Commissioner, who does not state in its Guidelines 9/2022 on the notification of personal data breaches under the General Data Protection Regulation that any unauthorised access should be recorded in the records of processing activities, but rather states that the controller may decide to document breaches within the framework of its records of processing activities, which it keeps in accordance with Article 30 of the General Data Protection Regulation. According to the liable party, case law (e.g. I Up 420/2000) also clearly distinguishes between the controller of a personal data file, who is authorised to create and keep records, and the user, who merely uses the data. 

13. Furthermore, in response to the information on the findings of …, the liable party gave its position regarding the notification of individuals, which, according to the liable party, should take place in accordance with Article 34 of the General Regulation. According to the liable party, individuals were duly informed about the incident in question by means of a press release, which clearly defined which individuals the incident concerned, namely those liable to be entered in the records …. The release made it clear which types of personal data were the subject of the incident. The liable party further states that the principle of ignorantia iuris nocet (ignorance of the law harms) applies in law, which means that an individual or legal entity cannot rely on ignorance of the fact that it is entered in the register, nor on ignorance of the obligations arising from this entry. Individuals are therefore obliged to know and monitor their obligations regarding entry in individual records. The liable party also states that although it does not have a list of names of the affected individuals, it estimates with a high degree of probability that they are liable persons entered in the said records. In view of the above, the liable party believes that the information provided to the public by … was sufficient, clear and understandable. The liable party further states that there was doubt about the identity of the individuals, because the requests were identical in content and were sent from the same email addresses, although they referred to different individuals. Most of the applications were sent from the email addresses of the provider …, whereby the identity of the senders could not be reliably verified based on the email address. The liable party allegedly acted in accordance with the IP guidelines (given in point 62 (b) of the document with the subject “Information with the findings and a call for clarification before a decision”, document number 0612-91/2025-33), according to which the controller is obliged to provide the individual with all available information at its disposal at a given moment. The liable party also states that no complaints were filed regarding the responses received. 

II. Requests from individuals 

Summary of the content of the requests from individuals, the taxpayer's responses to the individual and the taxpayer's explanations on the handling of the individual's request (given in the response to the information on the findings dated …)

14. On …, the taxpayer received a request from … asking whether she was concerned by the notification of unauthorized access to the taxpayer's information system and whether she should be concerned about the high risk of identity theft and misuse of personal data in the future. 

The taxpayer replied to the individual that the matter was under investigation, that he could generally say that there was no intrusion into individual collections, but into the unified record of entities from which various registers draw and update data on taxpayers, especially changes in residence and names, and that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. The taxpayer also added that he would inform the public about all relevant information after the investigation is complete. 

In response to the findings of …, the liable party stated that the party did not provide information about their place of residence in the application and explicitly stated that they did not want to provide the information. An application without an address is incomplete and is not suitable for substantive consideration. Without address information, it is also not possible to issue an administrative act (e.g. a request for supplementation or a decision), nor to ensure reliable identification. The individual's request was granted in the sense that she received a response with all available information. 

15. On …, the liable party received a request from …, which, based on Article 15 of the General Regulation, requested that the liable party confirm whether his personal data from the register … were disclosed or unlawfully made accessible to third parties and which data were exposed, during what period of time they were accessible and who had access or how the disclosure occurred. 

The taxpayer replied to the individual that the matter was under investigation and that he could generally say that there was no intrusion into individual collections, but into the unified record of entities from which various registers, including …, extract and update taxpayer data, especially changes in residence and names, and that, as stated in the press release, it concerns the first and last name, EMŠO, address and tax number. 

In response to the briefing on the findings dated …, the taxpayer stated that the party did not provide information about residence in the application, therefore identification is not possible, nor is it possible to issue an administrative act (e.g. a request for supplementation or a decision). The individual received a response with the available information. 

16. On …, the taxpayer received a request from …, which asked for information about whether her personal data had been disclosed, namely in connection with the entry … and the entry …. In the request, the individual indicated the period … and her tax number. 

The person liable replied to the individual that the matter was under investigation and that, based on the information known so far, he could confirm that personal data had also been disclosed...

In response to the disclosure of findings dated …, the taxpayer stated that the party identified itself as … and received a specific answer so that the taxpayer could confirm that personal data … had also been disclosed. 

17. On …, the taxpayer received a request from …, requesting information on whether his personal data had been disclosed, namely in connection with the entry of …. In the request, the individual indicated the period … and his tax number. 

The taxpayer replied to the individual that the matter was under investigation and that, based on the information known so far, he could confirm that personal data … had also been disclosed.

In response to the disclosure of findings dated …, the taxpayer stated that the party identified itself as … and received a specific answer so that the taxpayer could confirm that personal data … had also been disclosed.

18. On …, the taxpayer received a request from …, requesting information on whether his personal data was in the stolen data collection.

The taxpayer replied to the individual that the matter was under investigation and that he would inform the public of all relevant information once the investigation was completed. The taxpayer also replied that he could generally say that there was no hacking into individual collections, but into the unified record of entities from which various registers, including …, extract and update taxpayer data, especially changes in residence and names, and that as stated in the press release, this concerns the name and surname, EMŠO, address and tax number.

In response to the briefing on the findings dated …, the taxpayer stated that the party did not provide information on residence in the application, therefore identification is not possible, nor is it possible to issue an administrative act (e.g. a request for supplementation or a decision). The individual received a response with the available information. 

19. On …, the taxpayer received a request from …, which asked for information on whether his data was among those that were disclosed or whether a special verification procedure was planned. 

The taxpayer replied to the individual that the matter was under investigation and that he would inform the public of all relevant information after the investigation was completed. The taxpayer also replied that he could generally say that there was no intrusion into individual collections, but into a unified record of entities from which various registers, including …, draw and update data on taxpayers, especially changes in residence and names, and that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number.

In response to the information on the findings dated …, the taxpayer stated that the party did not provide information on residence in the application, therefore identification is not possible, nor is it possible to issue an administrative act (e.g. a request for supplementation or a decision). The individual received a response with the available information. The data subject also emphasized that the completeness of the application would not affect the information provided by the data subject in the press release or in the responses.

20. On …, the data subject received a letter from …, which, as an individual registered in the records kept by … and related authorities, requested the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data was included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach pursuant to Article 34 of the GDPR. The data subject provided his name and surname, permanent address, and e-mail address. The data subject's request bears the data subject's signature. 

The liable party replied to the individual that the investigation into the breach was still ongoing and that it would inform the public of all relevant information once the investigation was completed. The liable party also replied that it had stated in the public notice that the personal data of the liable parties (name, surname, tax number, EMŠO) were for entry into any register in the field of work …. If the individual is identified as a liable party in any of these collections, then there is a high probability that the unauthorised intrusion also included their personal data. 

In its response to the briefing on the findings dated …, the liable party stated that the party had stated in the application that it was entered into the records of … and that it had been given a specific answer that if the party identified itself as a liable party for entry into the records of …, there is a high probability that the unauthorised intrusion also included their personal data. 

21. On …, the liable party received a request from …, which requested confirmation that she was in the records that had been hacked and at the same time submitted a request to delete her data from the database and added that only information about the name, surname and permanent address would be allowed in the database.

The liable party replied to the individual that the investigation into the hack was still ongoing and that the public would be informed of all relevant information after the investigation was completed. The liable party added that it did not have information on the specific individuals affected, but according to the information known so far, these were persons liable for entry into the databases from the work area of …. 

In its response to the briefing on the findings dated …, the liable party stated that the party in the application itself had established that her data, because she was …, had been hacked, which the liable party confirmed to her in its response. The liable party will issue a decision regarding the request for deletion. 

22. On …, the liable party received a request from …, stating that she was interested in whether her personal data had been misused. She added that …. 

The liable party replied to the individual that, based on the information known so far, he could confirm that access to the personal data of … had also been enabled, but that he did not have any specific information. The investigation is still ongoing, and the public will be informed of all relevant information after the investigation is completed. 

In response to the disclosure of the findings on …, the liable party stated that the party had identified itself as … and had received a specific response that the liable party could confirm that the personal data of … had also been disclosed. The party did not provide information on residence as an essential component of the application in the administrative procedure. 

23. On …, the data subject received a letter from …, which, as an individual registered in the records kept by … and related authorities, invited the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data was included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach under Article 34 of the GDPR. The data subject provided his name and surname, permanent address, and email address. The data subject’s request bears his handwritten signature. 

The data subject replied to the data subject that the investigation into the breach was still ongoing and that he would inform the public of all relevant information once the investigation was completed. The taxpayer also replied that he stated in the public notice that the personal data of taxpayers (name, surname, tax number, EMŠO) for entry into any register from the field of work .... If an individual is identified as a taxpayer in any of these collections, then there is a high probability that the unauthorized intrusion also included his personal data. 

In response to the briefing on the findings of ..., the taxpayer stated that the client stated in the application that he was entered in the records of ... and that the taxpayer gave her a specific answer that if he identified himself as a taxpayer for entry, then there is a high probability that the unauthorized intrusion also included her personal data. 

24. On ..., the taxpayer received a letter from ..., which stated that he was ... and thus included in ... and asked for information on whether there had been unauthorized access to his personal data. 

The taxpayer replied to the individual that the matter was still under investigation and that he would inform the public of all relevant information after the investigation was completed. The taxpayer also replied that he could generally say that there was no intrusion into individual collections, but into a unified record of entities, from which various registers, including …, draw and update data on taxpayers, especially changes in residence and names. 

In response to the briefing on the findings dated …, the taxpayer stated that the party identified itself in the application as … and that it had only stated its first name, without its surname and address, so it was not possible to identify and issue an administrative act. The party received a response from which it follows that the data of the animal owners, including its data, had been disclosed. 

25. On …, the data subject received a letter from …, which, as an individual registered in the records kept by … and related authorities, invited the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data was included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach under Article 34 of the GDPR. The data subject provided his name and surname, address, email address and EMŠO. 

The data subject replied to the data subject that the matter was under investigation and that he would inform the public of all relevant information after the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into the unified record of entities, from which various registers, including ..., draw and update the data of taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated ..., the taxpayer stated that the party identified itself as the taxpayer for entry in the records ..., therefore only additional explanations were provided to it.The decision was not issued because its request was not rejected. 

26. On …, the data subject received a letter from …, which, as an individual registered in the records kept by … and related authorities, requested the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data were included in the scope of the unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach pursuant to Article 34 of the GDPR. The data subject provided his name and surname, address and email address. 

The data subject replied to the data subject that the matter was under investigation and that he would inform the public of all relevant information once the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into the unified record of entities, from which various registers, including ..., draw and update the data of taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated ..., the taxpayer stated that the party identified itself as the taxpayer for entry in the records ..., therefore only additional explanations were provided to it. The decision was not issued because her request was not rejected 

On 27. …, the data subject received a letter from …, which, as an individual registered in the records kept by .. and related authorities, requested the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of her personal data in connection with the security incident of … and requested the following information: Whether her data was included in the scope of the unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether she is entitled to a notification of the breach pursuant to Article 34 of the GDPR. The data subject provided her name and surname, address and e-mail address and signed the request. 

The data subject replied to the data subject that the matter was under investigation and that it would inform the public of all relevant information once the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into the unified record of entities, from which various registers, including ..., draw and update the data of taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated ..., the taxpayer stated that the party identified itself as the taxpayer for entry in the records ..., therefore only additional explanations were provided to it. The decision was not issued because its request was not rejected 

On 28. …, the liable party received a letter from …., which, as an individual registered in the records kept by … and related authorities, invited the liable party, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data were included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach pursuant to Article 34 of the GDPR. The individual provided his name, surname and address and signed the request. 

The liable party replied to the individual that the matter was under investigation and that he would inform the public of all relevant information once the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into the unified record of entities, from which various registers, including ..., draw and update the data of taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated ..., the taxpayer stated that the party identified itself as the taxpayer for entry in the records ..., therefore only additional explanations were provided to it. The decision was not issued because its request was not rejected 

On 29. …, the liable party received a letter from …, which, as an individual registered in the records kept by … and related authorities, invited the liable party, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data were included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach under Article 34 of the GDPR. The individual provided his name and surname, address, e-mail address and signed the request. 

The liable party replied to the individual that the matter was under investigation and that he would inform the public of all relevant information after the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into a unified record of entities, from which various registers, e.g. …, … … draw and update data on taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated …, the taxpayer stated that the party identified itself as the taxpayer for entry in the records of …, therefore only additional explanations were provided to it. The decision was not issued because her request was not rejected 

30. On …, the liable party received a letter from … requesting information on whether her personal data was among the disclosed data and, if the data was compromised, what types of data could be seen and what measures to protect individuals the liable party is introducing and whether the liable party intends to inform all individuals whose data was compromised. The individual provided her name and surname, date of birth, address and mobile phone number. 

The liable party replied to the individual that the matter was under investigation and that it would inform the public with all relevant information once the investigation was completed. The liable party also stated that, in general, it could be said that there was no intrusion into individual collections, but into the unified register of entities from which various registers, including …, extract and update the data of the liable parties, in particular changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the information on the findings dated …, the taxpayer stated that the client identified herself in the application as …. The client received a response from which it follows that the data …, including her data, were disclosed. 

31. On …, the taxpayer received a letter from …, which requested information on personal data, including the users of the data, and an explanation of the security incident in November 2025, specifically whether her personal data were included in the scope of data to which unauthorized access was enabled, which types of her personal data were included, whether the taxpayer identified and received information about the actual misuse of this data, and what measures the taxpayer took to ensure data security and prevent further risks. The individual provided information on her name and surname, address, date of birth and telephone number. 

The taxpayer replied to the individual that the matter was under investigation and that he would inform the public of all relevant information after the investigation was completed and that there were currently no indications that the data had been misused. The taxpayer also stated that he could generally say that there was no intrusion into individual collections, but into the unified register of entities, from which various registers extract and update data on taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this involved first and last name, social security number, address and tax number. The taxpayer additionally sent the individual a letter with the subject "Information on own personal data", the taxpayer's case number ..., in which he informed the individual that she was entered in ... and .... The taxpayer stated the legal basis for entry in the register and the types of personal data that are kept in the register on the basis of the law. The taxpayer also stated that data from ... is regularly transmitted to ... and added the legal basis for the said transmission.

In its response to the findings dated …, the liable party stated that the party had filed a request pursuant to Article 15 of the General Regulation and had received an appropriate response regarding the processing of personal data and users (whereas, in the opinion of the official, the attacker was not a user). The party was only given additional explanations regarding the intrusion, as it had already identified itself as the liable party for entry in the records …. 

32. On …, the data subject received a letter from …, which, as an individual registered in the records kept by … and related authorities, invited the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of his personal data in connection with the security incident of … and requested the following information: Whether his data was included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether he is entitled to a notification of the breach pursuant to Article 34 of the GDPR. The individual provided his name and surname, address, e-mail address and signed the request in his own handwriting.

The taxpayer replied to the individual that the matter was under investigation and that he would inform the public of all relevant information once the investigation was completed. The taxpayer also stated that he could generally say that there was no intrusion into individual collections, but into the unified register of entities, from which various registers extract and update data on taxpayers, especially changes in residence and names. The taxpayer added that, as stated in the press release, this involved first and last name, social security number, address, telephone number and tax number. 

In response to the information on the findings dated …, the taxpayer stated that the party had identified itself as a taxpayer for entry in the records …, therefore only additional explanations were provided to it. The decision was not issued because her request was not rejected 

33. On …, the data subject received a letter from …, which, as an individual registered in the records kept by .. and related authorities, requested the data subject, pursuant to Article 15 of the General Regulation, to be informed of the processing of her personal data in connection with the security incident of … and requested the following information: Whether her data was included in the scope of unauthorized access, which types of data were disclosed, when the access was carried out and for how long, whether the identity of the unauthorized user was established, what measures were taken to protect the data, whether there is a risk of further misuse or whether she is entitled to a notification of a breach pursuant to Article 34 of the GDPR. The data subject provided her name and surname, address, email address and telephone number and signed in her own handwriting. 

The data subject replied to the data subject that the matter was under investigation and that it would inform the public of all relevant information once the investigation was completed. The taxpayer also stated that in general, he can say that there was no intrusion into individual collections, but into the unified register of entities, from which various registers draw and update data on taxpayers, especially changes in residence and names. The taxpayer also added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. 

In response to the briefing on the findings dated …, the taxpayer stated that the party identified itself as the taxpayer for entry in the records …, therefore only additional explanations were provided to it. The decision was not issued because its request was not rejected 

34. On …, the liable party received a letter from …, which, on the basis of Article 15 of the General Regulation, requested information on whether his personal data were processed in the liable party’s databases, what types of personal data were processed, for what purposes they were processed, the users of the data, the source of the data, and information on whether his personal data had been involved/compromised in a security incident, as well as an assessment of the risk to the individual. The individual provided his name and surname and address. 

The liable party replied to the individual with an e-mail in which it stated that the matter was under investigation and that it would inform the public of all relevant information once the investigation was completed. The liable party also stated that it could generally say that there had been no intrusion into individual databases, but into the unified register of entities from which various registers, including …, draw and update data on the liable parties, in particular changes in residence and names. The taxpayer added that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. The taxpayer additionally sent the individual a letter with the subject “Information about own personal data”, the taxpayer’s case number …, in which he informed the individual that his personal data is processed in … where he is registered …. The purpose of the processing is …. He also stated that the individual provided the personal data to the taxpayer himself and that the taxpayer processes his personal name, address of residence, EMŠO, telephone number and e-mail address. The taxpayer stated that in addition to the taxpayer, certain users of the competent …, …, …, …, …, …. 

In his response to the briefing on the findings dated …, the taxpayer stated that the party had filed a request pursuant to Article 15 of the General Regulation and received an appropriate response regarding the processing of personal data and users (where, in the opinion of the official, the attacker is not a user). The client identified himself as the person liable for entry in the records of …, therefore he was only given additional explanations regarding the intrusion. No decision was issued, as his request was not rejected. 

35. On …, the person liable received a letter from …, requesting a printout of the accesses to his personal data (he is kept in the register of …) and information on whether his personal data had been accessed or stolen as part of the incident. 

The person liable replied to the individual that the matter was under investigation and that he could generally say that there had been no intrusion into individual collections, but into the unified register of entities, which contains the persons liable for entry in various collections/registers from the work area of the Ministry of Agriculture, and contains the name and surname, EMŠO, address and tax number. Various registers, including …, extract and update the data of the persons liable for entry from the register of entities, especially changes in residence and names. The intrusion into the records of entities is therefore not related to the traceability of the access to his personal data in …. The liable party also informed the individual that in order to obtain a printout of the access to his personal data, he must submit an application in accordance with the provisions of the General Administrative Procedure Act, which means that the individual's application must contain all the elements from Article 66 of the Act. 

In response to the information on the findings dated …, the liable party stated that the party did not indicate his place of residence in the application, and therefore the application was incomplete. The party received clear information about the possibility of supplementing the application, but the party did not respond. 

36. On …, the data subject received a letter from …, which requested, pursuant to Articles 15 and 17 of the General Regulation, the immediate and permanent deletion of all of his personal data from the data subject’s records, a specification of all of his personal data that had been disclosed in the breach, a precise legal explanation of why the data subject had stored his personal data, an explanation of the technical and organisational measures and an explanation of why these measures had failed, and the reasons why an appropriate security standard had not been ensured, given the scope, sensitivity and criticality of the data. 

The data subject sent the individual a letter with the subject “Information on own personal data”, the data subject’s case number …, in which it informed the individual that his personal data were being processed by …, and stated the legal basis for the processing of personal data, and informed the individual that none of the conditions for deletion under Article 17 of the General Regulation were met. Regarding the hack, he announced that the matter is under investigation and that he can generally say that there was no hack into individual databases, but into …, from which various registers extract and update data on taxpayers, especially changes in residence and names, and that, as stated in the press release, the disclosure of personal data concerns the name and surname, EMŠO, address and tax number. The public will be informed of all relevant information after the investigation is completed. 

In response to the briefing on the findings of …, the taxpayer stated that the party had filed a request under Article 15 of the General Regulation and received an appropriate response regarding the processing of personal data and users (whereas, according to the official, the attacker is not a user). The party identified itself as the party required to enter data into the records of …, therefore, it was only given additional explanations regarding the hack. A decision will be issued to the party regarding the request for deletion. 

37. On …, the data subject received a request … for access to personal data, in which he requested access to all categories of data recorded by the data subject about him, the purposes of processing, the legal basis for processing, the retention period and users, and an explanation of the security incident, namely whether his personal data were included in the scope of data to which unauthorized access was granted, which types of his personal data were included, whether the data subject received information about the actual misuse of the data, and the measures taken by the data subject to ensure data security and prevent further risks. The individual provided his name and surname, address, date of birth and mobile number. 

The data subject replied to the individual that the matter was under investigation, that he would inform the public of all relevant information after the investigation was completed, and that there were currently no indications that the data had been misused. The taxpayer added that he can generally say that there was no intrusion into individual collections, but into a unified record of entities, from which various registers extract and update data on taxpayers, especially changes in residence and names, and that, as stated in the press release, this concerns the name and surname, EMŠO, address and tax number. The taxpayer also stated that all the information at their disposal is included in the press release and that the taxpayer has no information about whether the individual's personal data is specifically subject to unauthorized access. However, since the individual is required to be entered in the central register ..., there is a high probability that the individual's personal data was also disclosed. The taxpayer also sent the individual a letter with the subject "Information about your own personal data", the taxpayer's case number ..., in which he informed the individual that his personal data was being processed in the Central Register ..., stated the purpose of the processing and the legal basis for the processing, and the types of personal data that the taxpayer processes. The liable party stated that in addition to the liable party, certain users of the competent …, …, …, …, …. The liable party also stated the retention period for personal data. 

In its response to the information on the findings dated …, the liable party stated that the party had filed a request pursuant to Article 15 of the General Regulation and had received an appropriate response regarding the processing of personal data and users (whereas, in the opinion of the official, the attacker was not a user). The party had identified itself as the liable party for the entry in the records of …, and therefore only additional explanations were provided regarding the intrusion. No decision was issued, as the request was not rejected. 

Assessment of the requests of individuals and the responses of the liable party

After reviewing the requests of individuals and the responses of the liable party, the State Supervisory Authority finds:

38. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. The liable party responded to the request with a general response, which contained only a statement of facts of a general nature, but not facts that would specifically, explicitly and unambiguously refer to the personal data of the individual.

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the data subject to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the data subject did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The data subject’s claim that the individual’s request was granted is incorrect. The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The client stated in her application that she was interested in how she could find out whether her personal data had been disclosed to third parties without authorisation and to which third parties, if she did not wish to provide her personal data for obvious security reasons.

The liable party understood this to mean that the client had explicitly refused to provide information on her place of residence, and therefore considered her application to be incomplete and, as such, unsuitable for substantive consideration. She further explained that, due to the absence of information on her place of residence, it was not possible to issue an administrative act (e.g. a request for completion or a decision).

The State Supervisor finds that such a summary and understanding of the party's statement does not follow the principle of protecting the rights of the party from Article 7 of the General Administrative Procedure Act (Official Gazette of the Republic of Slovenia, No. 24/06 – official consolidated text, 105/06 – ZUS-1, 126/07, 65/08, 8/10, 82/13, 175/20 – ZIUOPDVE, 3/22 – ZDeb and 85/25; hereinafter: ZUP). When proceeding and making decisions, the authorities must enable the parties to protect and enforce their rights as easily as possible. The liable party did not do this, as it did not inform the party that it must provide information on its place of residence in order to process the application, nor did it warn it that the application would be incomplete without this information and therefore unsuitable for substantive processing, and that it would therefore not be possible to issue an administrative act.

In accordance with the sixth paragraph of Article 12 of the General Regulation, if the obliged party had justified doubts about the identity of the individual, he could request additional information necessary to confirm the identity. However, he did not invite the party to provide additional information or to correct the deficiencies in the application (i.e. to provide information on the place of residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must invite the applicant to correct the deficiencies and set a deadline for completion. Only if the applicant fails to correct the deficiencies within the specified deadline may the authority reject the application by decision.

39. The request received on …. constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. The data subject responded to the request with a general response, which contained only a statement of facts of a general nature, but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual.

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the data subject to obtain all available information on whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the data subject therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party was not concrete, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

In relation to the statement of the liable party that the party did not indicate their place of residence in the application and therefore identification is not possible, nor is the issuance of an administrative act possible, the State Supervisor establishes that the liable party's position is not in accordance with the principle of protection of the rights of parties from Article 7 of the ZUP. When proceeding and making decisions, authorities must enable parties to protect and enforce their rights as easily as possible. The liable party did not do this, as it did not inform the party that they must provide information on their place of residence in order to process the application, nor did it warn them that without this information, the party's identification is not possible and that it will therefore not be possible to issue an administrative act.

In accordance with the sixth paragraph of Article 12 of the General Regulation, if the obliged party had justified doubts about the identity of an individual, he could request additional information necessary to confirm the identity. However, he did not invite the party to provide additional information or to correct the deficiencies in the application (i.e. to provide information on the place of residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must invite the applicant to correct the deficiencies and set a deadline for completion. Only if the applicant fails to correct the deficiencies within the specified deadline may the authority reject the application by decision.

40. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The responsible party responded to the request with a general response, which contained only a statement of facts of a general nature (that the personal data of the owners … were also disclosed), but not facts that would specifically, explicitly and unambiguously refer to the personal data of the individual (i.e. that her personal data were disclosed).

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the responsible party to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who, in the security breach, had unlawfully accessed the data in table …. Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in the table … on … and therefore her personal data were shown to the person who, in a security breach, unlawfully accessed the data in the table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

41. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The responsible party responded to the request with a general response, which contained only a statement of facts of a general nature (that personal data were also disclosed ...), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that his personal data were disclosed). 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the responsible party to obtain all available information about whether the individual was entered in table ... on ... and therefore the individual's personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table .... Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in table … on … and therefore the individual’s personal data were shown to the person who, in a security breach, unlawfully accessed the data in table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

42. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The data subject responded to the request with a general response, which contained only a statement of facts of a general nature, but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual.

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the data subject to obtain all available information on whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who, in the security breach, had unlawfully accessed the data in table …. Since such measures were not implemented, the data subject therefore did not provide the individual with all available information related to establishing the fact whether the individual was … on …. entered in the table … and therefore the individual's personal data were displayed to the person who, in a security breach, unlawfully accessed the data in the table …. 

The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party is not concrete, explicit and unambiguous. At the same time, I found that no refusal decision was issued in accordance with Article 13 of the ZVOP-2.

Regarding the taxpayer's statement that the party did not indicate their place of residence in the application and therefore identification is not possible, nor is the issuance of an administrative act possible, the State Supervisor finds that the taxpayer's position is not in accordance with the principle of protection of the rights of parties from Article 7 of the ZUP. In the course of proceedings and decision-making, authorities must enable parties to protect and enforce their rights as easily as possible. The taxpayer did not do this, as he did not inform the party that he must provide information on his place of residence in order to process the application, nor did he warn him that without this information the party's identification is not possible and that it will therefore not be possible to issue an administrative act.

In accordance with the sixth paragraph of Article 12 of the General Regulation, the taxpayer could request additional information necessary to confirm the identity if he had justified doubts about the identity of an individual. However, he did not invite the party to provide additional information nor did he invite him to eliminate the deficiencies in the application (i.e. to provide information on his place of residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must request the applicant to remedy the deficiencies and set a deadline for completion. Only if the applicant fails to remedy the deficiencies within the specified deadline may the authority reject the application by decision.

43. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The obligated party responded to the request with a general response that contained only a statement of facts of a general nature, but not facts that would specifically, explicitly and unambiguously refer to the personal data of the individual.

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

In relation to the statement of the liable party that the party did not indicate their place of residence in the application and therefore identification is not possible, nor is the issuance of an administrative act possible, the State Supervisor finds that the liable party's position is not in accordance with the principle of protection of the rights of parties from Article 7 of the ZUP. When proceeding and making decisions, the authorities must enable parties to protect and enforce their rights as easily as possible. The liable party did not do this, as it did not inform the party that they must provide information on their place of residence in order to process the application, nor did it warn them that without this information the party's identification is not possible and that it will therefore not be possible to issue an administrative act.

In accordance with the sixth paragraph of Article 12 of the General Regulation, the liable party, if it had justified doubts about the identity of an individual, could request additional information necessary to confirm the identity. However, the party was not asked to provide additional information or to correct the deficiencies in the application (i.e. to provide information on residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must ask the applicant to correct the deficiencies and set a deadline for completion. Only if the applicant fails to correct the deficiencies within the specified deadline can the authority reject the application by decision.

44. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The obligated party responded to the request in an ambiguous manner (if the party identifies itself as the obligated party for registration, then it is highly likely that the unauthorized intrusion also included its personal data). 

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to eliminate the deficiencies in the application.

45. The request received on … … constitutes a request under Article 15 of the General Regulation (explicitly requesting information on the user of personal data) and under Article 17 of the General Regulation (request for deletion) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

In response to the request, the liable party replied that they did not have data on specific individuals. The statement of the liable party (from the response to the acknowledgment of findings dated …) that it confirmed to the party in its response that her data had been hacked because she was the owner of a dog is not true. 

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no refusal decision was issued in accordance with Article 13 of the ZVOP-2.

The individual's request under Article 17 of the General Regulation was not decided. 

The obligated party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

46. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The obligated party responded to the request in an ambiguous manner (based on the information known so far, it can confirm that access to personal data was enabled …), but not specifically and explicitly regarding the individual (i.e. whether her personal data was affected by the breach) and at the same time stated that it did not have any specific information. 

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

In relation to the obligor's statement that the party did not indicate the place of residence as an essential component of the application in the administrative procedure, the State Supervisor finds that the authorities must enable the parties to protect and enforce their rights as easily as possible when proceeding and making decisions. The obligor did not inform the party that he must provide information on his place of residence in order to process the application.

In accordance with the sixth paragraph of Article 12 of the General Regulation, the obligor could request additional information necessary to confirm the identity if he had justified doubts about the identity of the individual. However, he did not invite the party to provide additional information or to eliminate the deficiencies in the application (i.e. to provide information on his place of residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must request the applicant to remedy the deficiencies and set a deadline for completion. Only if the applicant fails to remedy the deficiencies within the specified deadline can the authority reject the application by decision.

47. On … the request received … constitutes a request under Article 15 of the GDPR (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the GDPR. 

The data subject responded to the request in an ambiguous manner (if the party identifies itself as the data subject for registration, then it is highly likely that the unauthorized intrusion also included their personal data). 

Regarding the communication to the individual pursuant to Article 34 of the GDPR: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual’s personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the data subject to obtain all available information on whether the individual was registered in table … on … and therefore the individual’s personal data were displayed to the person who, in the security breach, had unauthorized access to the data in table …. Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in the table … on … and therefore the individual’s personal data were shown to the person who, in a security breach, unlawfully accessed the data in the table …..

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

48. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The data subject responded to the request with a general response, which contained only a statement of facts of a general nature (so that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on data subjects), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that her personal data were disclosed). 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the data subject to obtain all available information about whether the individual was entered in table … on … and therefore her personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table …. Since such measures were not implemented, the liable party did not provide the individual with all the information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were shown to the person who, in a security breach, unlawfully accessed the data in table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not concrete, explicit and unambiguous. At the same time, I found that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

In relation to the liable party’s statement that the party only provided her name in the application, which made it impossible to issue an administrative act and identify her, the State Supervisor finds that authorities must enable parties to protect and enforce their rights as easily as possible when proceeding and making decisions. The liable party did not inform the party that they must provide information on their surname and place of residence in order to process the application.

In accordance with the sixth paragraph of Article 12 of the General Regulation, if the obliged party had justified doubts about the identity of the individual, he could request additional information necessary to confirm the identity. However, he did not invite the party to provide additional information or to correct the deficiencies in the application (i.e. to provide information on the surname and place of residence).

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must invite the applicant to correct the deficiencies and set a deadline for completion. Only if the applicant fails to correct the deficiencies within the specified deadline may the authority reject the application by decision.

49. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The data subject responded to the request with a general response, which contained only a statement of facts of a general nature (so that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on data subjects), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that her personal data were disclosed).

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the data subject to obtain all available information about whether the individual was entered in table … on … and therefore her personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table …. Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in the table … on … and therefore her personal data were shown to the person who, in a security breach, unlawfully accessed the data in the table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

50. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The data subject responded to the request with a general response, which contained only a statement of facts of a general nature (so that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on data subjects), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that his personal data were disclosed).

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the data subject to obtain all available information about whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table …. Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in table … on … and therefore the individual’s personal data were shown to the person who, in a security breach, unlawfully accessed the data in table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that a rejection decision was not issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

51. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The data subject responded to the request with a general response, which contained only a statement of facts of a general nature (so that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on data subjects), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that her personal data were disclosed).

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organizational measures were implemented to enable the data subject to obtain all available information about whether the individual was entered in table … on … and therefore her personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table …. Since such measures were not implemented, the liable party therefore did not provide the individual with all the information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who, in a security breach, unlawfully accessed the data in table ….

The individual's request under Article 15 of the General Regulation was not granted, as the liable party's response was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did it ask the individual to remedy the deficiencies in the application.

52. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response, which contained only a statement of facts of a general nature (so that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on liable parties), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that his personal data had been disclosed).

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to remedy the deficiencies in the application.

53. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response, which contained only a statement of facts of a general nature (that it can generally state that there was no hacking into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on liable parties), but not facts that would specifically, explicitly and unambiguously relate to the individual's personal data (i.e. that his personal data was disclosed).

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to remedy the deficiencies in the application.

54. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response, which contained only a statement of facts of a general nature (that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on liable parties), but not facts that would specifically, explicitly and unambiguously relate to the personal data of the individual (i.e. that her personal data was disclosed).

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The taxpayer did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to remedy the deficiencies in the application.

55. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information on whether the third party who accessed the taxpayer's information systems without authorisation is a user of her personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The taxpayer responded to the request with a general response by e-mail and with a letter with the subject "Information on own personal data", the taxpayer's case number ..., whereby in none of the letters did he answer the question of whether the third party who accessed the taxpayer's information systems without authorisation is a user of her personal data. As will be explained in points 96 to 102 of the reasoning of this decision, the liable party's view that the attacker is not the data user is incorrect. 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the liable party to obtain all available information on whether the individual was on … entered in table … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the liable party therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party is not specific, explicit and unambiguous. At the same time, I found that no refusal decision was issued in accordance with Article 13 of the ZVOP-2.

56. The request received on … … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response, which contained only a statement of facts of a general nature (that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on liable parties), but not facts that would specifically, explicitly and unambiguously relate to the individual's personal data (i.e. that his personal data was disclosed).

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The liable party did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to remedy the deficiencies in the application.

57. The request received on … constitutes a request under Article 15 of the General Regulation (it explicitly requests information about the user of personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response, which contained only a statement of facts of a general nature (that it can generally state that there was no intrusion into individual collections, but into a single record of entities from which various registers, including the Central Register …, draw and update data on liable parties), but not facts that would specifically, explicitly and unambiguously relate to the individual's personal data (i.e. that her personal data had been disclosed).

Regarding the communication to the individual pursuant to Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether her personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore her personal data were displayed to the person who had unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the answer of the obliged entity was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

The taxpayer did not ask the individual to provide additional information for the purpose of identifying the individual, nor did he ask the individual to remedy the deficiencies in the application.

58. The request received on … … constitutes a request under Article 15 of the General Regulation (which, among other things, explicitly requests information on whether the third party who accessed the taxpayer's information systems without authorisation is a user of their personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The taxpayer responded to the request with a general response by e-mail and with a letter with the subject "Information on own personal data", the taxpayer's case number ..., whereby in none of the letters did he answer the question of whether the third party who accessed the taxpayer's information systems without authorisation is a user of the individual's personal data. As will be explained in points 96 to 102 of the reasoning of this decision, the liable party's view that the attacker is not the data user is incorrect. 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the liable party to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the liable party therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the liable party's response was not specific, explicit and unambiguous. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

59. The request received on … constitutes a request under Article 15 of the General Regulation (which, among other things, explicitly requests information on whether a third party who has unauthorized access to the liable party's information systems is a user of their personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a general response (that it can generally state that there was no intrusion into individual databases, but into a single register of entities, which contains liable parties entered in various databases/registers from the field of work …. Various registers, including the Central Register …, draw and update data on liable parties from the register of entities). The liable party further stated that the intrusion into the records of entities was not related to the traceability of the access to his personal data in the register … and informed him, in relation to obtaining a printout of access to his personal data, that he must submit an application in accordance with the provisions of the General Administrative Procedure Act. The liable party therefore did not inform the individual that he considered his application to obtain information on whether his personal data had been accessed or stolen as part of the incident to be incomplete and that the individual must provide additional information so that an administrative act could be issued or the individual could be unambiguously identified. The State Supervisor finds that the liable party did not act in accordance with the principle of protection of the rights of parties set out in Article 7 of the ZUP in relation to the individual's request (regarding the question of whether the individual's personal data had been accessed or stolen as part of the incident). When acting and making decisions, authorities must enable parties to protect and enforce their rights as easily as possible. The liable party did not do this, as it did not inform the party that it had to provide additional information in order to process the application (regarding the question of whether the individual's personal data were accessed or stolen as part of the incident), nor did it warn the party that without additional information, the party's identification was not possible and that it would therefore not be possible to issue an administrative act.

In accordance with the sixth paragraph of Article 12 of the General Regulation, the liable party could, if it had justified doubts about the identity of the individual, request additional information necessary to confirm the identity. However, it did not invite the party to provide additional information (for the purpose of processing the question of whether the individual's personal data were accessed or stolen as part of the incident) nor did it invite it to remedy the deficiencies in the application (for the purpose of deciding on the question of whether the individual's personal data were accessed or stolen as part of the incident). 

In accordance with Article 67 of the ZUP, an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must request the applicant to remedy the deficiencies and set a deadline for completion. Only if the applicant fails to remedy the deficiencies within the specified deadline may the authority reject the application by decision.

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, additional technical and organisational measures were also not implemented in order for the obliged entity to obtain all available information on whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table …. Since such measures were not implemented, the obliged entity therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore the individual's personal data were displayed to the person who, in the security breach, unlawfully accessed the data in table ….

The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party is not concrete, explicit and unambiguous. At the same time, I have established that no refusal decision was issued in accordance with Article 13 of the ZVOP-2.

60. The request received on … constitutes a request under Article 15 of the General Regulation (which, among other things, explicitly requests information on whether a third party who has unauthorized access to the liable party's information systems is a user of their personal data), a request under Article 17 of the General Regulation (requests the deletion of personal data) and at the same time establishes the obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request with a letter with the subject “Information with own personal data”, liable party’s case number …., in which it rejected the individual’s request for deletion and at the same time did not answer the question of whether the third party who had unauthorized access to the liable party’s information systems was a user of the individual’s personal data. As will be explained in points 96 to 102 of the reasoning of this decision, the liable party’s view that the attacker was not a user of the data is incorrect. 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a concrete, explicit and unambiguous answer to the question of whether the individual’s personal data was affected by the security breach. In relation to a specific individual, no additional technical and organisational measures were implemented to enable the liable party to obtain all available information on whether the individual was entered in table … on … and therefore the individual’s personal data were displayed to the person who, in a security breach, unlawfully accessed the data in table ….. Since such measures were not implemented, the liable party therefore did not provide the individual with all information related to establishing the fact whether the individual was entered in table … on … and therefore the individual’s personal data were displayed to the person who, in a security breach, unlawfully accessed the data in table ….

The individual’s request under Article 15 of the General Regulation was not granted, as the liable party’s response was not specific, explicit and unambiguous. At the same time, I established that no refusal decision was issued in accordance with Article 13 of the ZVOP-2. 

The individual's request under Article 17 of the General Regulation was rejected, but no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

61. The request received on … constitutes a request under Article 15 of the General Regulation (which, among other things, explicitly requests information on whether a third party who has unauthorized access to the information systems of the liable party is a user of their personal data) and at the same time establishes an obligation to notify the individual under Article 34 of the General Regulation. 

The liable party responded to the request by e-mail and with a letter with the subject "Information with own personal data", the liable party's case number .... By e-mail, the liable party stated that it had no information on whether the individual's personal data were specifically subject to unauthorized access, but since the individual is obliged to enter the central register ..., there is a high probability that the individual's personal data were also disclosed. As will be explained in points 96 to 102 of the reasoning of this decision, the liable party's view that the attacker is not the data user is incorrect. 

Regarding the communication to the individual in accordance with Article 34 of the General Regulation: The individual was not provided with a specific, explicit and unambiguous answer to the question of whether the individual's personal data were affected by the security breach. In relation to the specific individual, no additional technical and organisational measures were implemented to enable the liable party to obtain all available information on whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach. Since such measures were not implemented, the liable party therefore did not provide the individual with all information related to establishing the fact whether the individual was on … entered in table … and therefore the individual's personal data were displayed to the person who unlawfully accessed the data in table … in the security breach.

The individual's request under Article 15 of the General Regulation was not granted, as the response of the liable party is not concrete, explicit and unambiguous, therefore the statement of the liable party (given in the response to the information on the findings dated …) that the individual's request was not rejected is not true. At the same time, I found that no rejection decision was issued in accordance with Article 13 of the ZVOP-2.

III. Legal basis for the assessment of the lawfulness of data processing and the supervisor's findings

62. In this inspection procedure, the supervisor primarily checked the compliance of the liable party's actions with Articles 12, 15, 17, 32 and 34 of the General Regulation. 

Point I. of the operative part

63. The General Regulation provides in Article 32:
"1. Taking into account the state of the art and the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the risks to the rights and freedoms of individuals, which vary in likelihood and severity, the controller and the processor shall ensure a level of security appropriate to the risk by implementing appropriate technical and organisational measures, including, inter alia, the following measures, as appropriate:

(a) pseudonymisation and encryption of personal data;

(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of the systems and services for processing;

(c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;

(d) a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures to ensure the security of processing.

2. In determining the appropriate level of security, account shall be taken in particular of the risks presented by the processing, in particular against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.

3. Adherence to an approved code of conduct referred to in Article 40 or the implementation of an approved certification mechanism referred to in Article 42 may be used to demonstrate compliance with the requirements set out in paragraph 1 of this Article.

4. The controller and the processor shall ensure that any natural person acting under the direction of the controller or the processor who has access to personal data shall not process the personal data without instructions from the controller, unless required to do so by Union or Member State law.

64. Article 5(1)(f) of the GDPR provides that personal data shall be processed in a manner which ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage by appropriate technical or organisational measures (‘integrity and confidentiality’).

65. The personal data controller is obliged to ensure the confidentiality of personal data and is at the same time obliged to carry out procedures for regular testing, assessment and evaluation of the effectiveness of technical and organisational measures to ensure the security of processing. One of the key measures in ensuring the security of personal data is the principle of limited access to information, which is ensured, among other things, by access rights in such a way that users (including system and application users) have access to personal data only if the users absolutely need such access to perform their tasks. In order for controllers to effectively manage access rights, controllers must establish and implement an access rights policy that specifies how access rights are provided, reviewed, modified and removed. Access rights management policies are a fundamental and long-established information security standard that is systematically used in international frameworks, such as ISO/IEC 27001 and ISO/IEC 27002. For example, control A.5.18 (Access rights) of ISO/IEC 27001:2022 states that access rights to information and other related assets should be granted, reviewed, modified and removed in accordance with the organization's area policy and access control rules. The same is stated in the Cybersecurity Manual, published in November 2025 by the Information Security Office of the Government of the Republic of Slovenia, which recommends that the core areas that the overarching security policy should include include an Access Control Policy, which should contain at least: (i) User authentication: requirements for user authentication mechanisms, such as passwords, multi-factor authentication and biometric controls. (ii) Authorization: procedures for granting, changing and revoking access rights to systems and data and (iii) Account management: procedures for managing user accounts, including regular reviews of access rights and timely removal of access for dismissed employees.

66. It follows from the statements of the liable party that the personal data security breach occurred via the data view …, to which the user … should not have had access. Given the purpose of the application, the user … should not have had approved access rights to the personal data that were accessible via the said view. The State Supervisor finds that the liable party, by carrying out regular reviews of access rights, which should also include a review of the access rights of application users, could have determined in a timely manner that the user … had been granted access rights that, given the purpose of the application, should not have been granted. This could have effectively prevented an attacker from accessing the personal data of natural persons, which were kept in the table …, through the user … using the data view ….

67. In connection with the above, I therefore checked whether the liable party has taken appropriate technical and organisational measures to ensure that a similar violation, which could be possible due to inappropriately granted access rights, could not be repeated in the future. In doing so, I checked whether the liable party has established an access control policy, which would specify procedures for granting, changing and revoking access rights and for regular reviews of granted access.

68. The State Supervisor notes that the liable party has partially established an access control policy. The liable party has adopted Instructions for granting rights and authorisations by …. and …, which regulate the procedure for granting and revoking access rights to designated users (users who are natural persons) on the basis of a notification of a change of user, termination of employment, abuse of rights, prolonged absence or death.

69. At the same time, I note that the liable party has not established a procedure for granting and revoking access rights to application users, including user …, in the adopted policies, and has not established an obligation to regularly review access rights. The liable party has partially regulated the obligation to regularly review access rights of designated users (natural persons) by …, where it is stipulated that a monthly inquiry for deceased users and locking of their accounts is to be carried out, as well as periodic calls to organizations to update the list of active users. The liable party stated that the provision on periodic reviews of access rights, as defined in the Instructions for granting rights and authorizations by …, where this is reasonable, also applies to all information systems of the liable party, whereby the liable party did not refer to a provision of internal policy or instructions that would stipulate the reasonable application of the provisions applicable to … in connection with other information systems of the liable party. The mere sensible implementation of the provision on regular review of access rights, which is not established as an obligation in the internal acts of the liable entity, is not sufficient, especially considering the fact that the liable entity suffered a security breach that could have been prevented by introducing mandatory regular reviews of access rights.

70. In conclusion, the State Supervisor finds that the liable entity has not established an appropriate access control policy, as it has only partially established the rules on regular review of access rights of individual users (natural persons), while it has not established the rules on regular review of access rights of application users at all. In addition, the liable entity has not established rules regarding the allocation, withdrawal and modification of access rights of application users. Taking into account the types of personal data processed by the data subject (name, surname, address, tax number, EMŠO number) and the large number of individuals to whom these personal data relate, and the fact that the failure to perform a regular review of application access rights has enabled a breach of personal data security, I conclude that the data subject must establish and implement such rules in the future in order to ensure compliance with the requirements of Article 32 of the General Regulation. 

71. Due to the identified irregularities, the data subject had to be ordered, on the basis of point 1 of the first paragraph of Article 29 of the ZVOP-2, the first paragraph of Article 32 of the ZIN and point (d) of the second paragraph of Article 58 of the General Regulation, to eliminate the identified irregularities and to align the personal data processing operations with the provisions of the General Regulation in the manner specified in point I of the operative part of this decision, namely within the time limit specified in point V of the operative part of this decision.

Point II. operative part

72. In response to the information on the findings of …, the liable party stated that there was doubt regarding the identity of the individuals, because the requests were identical in content and were sent from the same email addresses, although they referred to different individuals. Most of the applications were sent from the email addresses of the provider …, whereby the identity of the senders could not be reliably verified based on the email address. The liable party also stated that certain individuals did not indicate their place of residence, therefore the identification of the individuals was not possible and at the same time the issuance of an administrative act (e.g. a request for supplementation or a decision) was not possible. The liable party's statements are summarised in points 14 to 37 of this decision. 
73. In accordance with the sixth paragraph of Article 12 of the General Regulation, the liable party, if it had justified doubts about the identity of the individual, could request additional information necessary to confirm the identity. At the same time, Article 67 of the ZUP also stipulates that an application that is incomplete or incomprehensible may not be rejected solely for this reason. The authority must invite the applicant to correct the deficiencies and set a deadline for completion. Only if the applicant fails to correct the deficiencies within the specified deadline can the authority reject the application by decision. The claim that the taxpayer could not invite the individual to complete the application simply because the taxpayer did not indicate his or her place of residence in the application is incorrect. Namely, individuals submitted applications to the taxpayer by e-mail, so the taxpayer could send the invitation to complete the application to the individuals to the e-mail address from which the individuals submitted the applications. This is regulated by Article 86, paragraph 2, of the ZUP. 

74. After reviewing the taxpayer's responses to individuals, the State Supervisor establishes that the taxpayer sent a letter to certain individuals with the subject "Information with own personal data", based on which I establish that he did not doubt the identity of these individuals. Furthermore, the State Supervisor establishes that the taxpayer did not ask the remaining individuals to provide additional information or to correct the deficiencies in the application (for example, to provide information about their place of residence). The Supervisor's findings in relation to each individual request from the individual are presented in points 38 to 61 of this decision. In accordance with the sixth paragraph of Article 12 of the General Regulation, if the taxpayer assessed that he had justified doubts regarding the identity of the individual who submitted the request, he should have requested that he provide additional information necessary to confirm his identity, which he did not do.

75. Taking into account the above, the liable party had to be ordered, on the basis of point 1 of the first paragraph of Article 29 of the ZVOP-2, point 1 of Article 32 of the ZIN and point (d) of the second paragraph of Article 58 of the General Regulation, to eliminate the identified irregularities and to harmonize the personal data processing activities with the provisions of the General Regulation in the manner specified in point II of the operative part of this decision, namely within the period specified in point VI of the operative part of this decision.

Point III of the operative part

Regarding the notification of individuals in accordance with Article 34 of the General Regulation 

76. In its response of …, the liable party stated that it had fulfilled the obligation to notify individuals under Article 34 of the General Regulation in accordance with point c) of the third paragraph of this Article. 

77. Article 34(3)(c) provides that the communication to the data subject referred to in Article 34(1) is not required if this would involve a disproportionate effort and that in such a case a public notice shall be published instead or a similar measure shall be taken by which the data subjects are informed in an equally effective manner. In order for the data subject to provide the information in accordance with Article 34(3)(c), two conditions must be cumulatively met: (i) informing each individual constitutes a disproportionate effort and (ii) a public notice shall be published or a similar measure shall be taken by which the data subjects are informed in an equally effective manner. The State Supervisor finds, with regard to the first condition, that informing each of … individuals by means of a separate notice would be considered to constitute a disproportionate effort. The State Supervisor then determined whether the individuals were informed in an equally effective manner by means of a public notice. I assessed the above based on the public announcement of the liable party and the requests and applications received from individuals in which they requested that the liable party explain whether their personal data were affected by the security breach.

78. The liable party stated in the public announcement that, through the website where the list of registered … is published, unauthorized access was enabled to the personal data of … natural persons (name, surname, address, EMŠO and tax number), who were in the past obliged to be entered in the registers kept by … and bodies within the Ministry (…) in accordance with the relevant legislation or who were subject to inspection supervision in the field of …. This includes, among other things, registers …, registers …, recipients, pet register, etc. This concerns data of liable parties who are entered in the records of entities pursuant to the Agriculture Act and related laws and implementing regulations. The data subject also stated that individuals who identify themselves in these databases can contact the email address for additional information….

79. The State Supervisor notes that, from the perspective of the individual, the same effectiveness of notification is achieved only if the individual understands, on the basis of the public notice, that the notification of the breach concerns him or her or his personal data, and is therefore aware of the risk to his or her rights and freedoms. The fact that the individual addresses the data subject with an explicit question as to whether his or her personal data have been affected shows that the individual could not have ascertained this fact on the basis of the information in the public notice. In such a case, the data subject is obliged to provide the individual with a specific, explicit and unambiguous answer that expressly relates to the individual’s personal data. If the data subject fails to provide such an answer, it cannot be considered that the individuals concerned have been informed in an equally effective manner, which means that it has failed to fulfil the notification obligation under Article 34 of the General Regulation in relation to the individuals concerned.

80. In its response of …, the liable party stated that it provided individual responses to all individuals who contacted the liable party with a question about whether their personal data were included in the personal data that was the subject of the attack, including all the information that they had at the time of the response. 

81. The State Supervisor notes that the aforementioned argument does not absolve the liable party from its obligations under Article 34 of the General Regulation. From the perspective of handling a security breach and informing individuals, it is not sufficient for the liable party to provide only the information that it has at the time of the response, but it is also obliged to actively obtain this information to the extent that it enables effective notification of individuals about the security breach. The liable party must, in accordance with the fifth paragraph of Article 33 of the General Regulation, document the personal data protection breach, including the facts of the breach, its effects and the corrective measures taken. In view of the obligation to inform individuals under Article 34 of the GDPR, the facts and effects of the breach must also include information on which individuals were affected by the breach. The data subject is therefore obliged to document the facts on the basis of which it is possible to establish which individuals were affected by the security breach in order to be able to fulfil his obligation under Article 34 of the GDPR.

82. The establishment and obtaining of facts on the affected individuals is also required in accordance with Article 5(2) of the GDPR in conjunction with point a) of Article 5(1) of the GDPR, which stipulates that personal data must be processed fairly and in a transparent manner. In accordance with this principle, the controller must act fairly and honestly not only when processing the personal data of individuals in accordance with the regulations, but also, and even more so, in the event of unlawful processing of the personal data of individuals, in particular if this is the result of irregularities on the part of the controller. In this case, the controller must do everything in its power to ensure that the affected individuals have their right to information under Article 34 of the General Regulation to the greatest extent possible. While it can be accepted that the identification of all individuals to whom personal data relate by the data subject would require a disproportionate effort within the meaning of point c) of the second paragraph of Article 34 of the General Regulation, this is by no means the case with regard to the identification of the twenty-four individuals who submitted applications to the data subject in this regard. In relation to the latter, the data subject was obliged to make a reasonable effort to determine whether their personal data had also been unlawfully processed and to inform them accordingly, as such an effort is by no means disproportionate. As will be explained below, the data subject did not demonstrate in the proceedings that he had made any effort in the aforementioned determination or that he had taken any active approach to such determination. The purpose of notifying individuals about a security breach is to make them aware of the risks to their rights and freedoms, which they can only achieve if they know that the breach directly affects them. Therefore, fair and transparent notification is only ensured if the obligated party, on whose side such risks to individuals have arisen, implements all available technical and organizational measures to determine which individuals have been affected and provides them with this information in a fair and transparent manner. Given the circumstances of the specific case, the obligated party should fulfill this obligation particularly consistently and act particularly carefully when providing information to individuals. In the case at hand, it is impossible to overlook the fact that there was an interference with the constitutional right to the protection of personal data of an exceptionally large number of individuals, that such an interference occurred due to the inadequate provision of personal data security by the obligated party, and that the obligated party is a state authority entrusted with the management of a database in which, among other things, the personal data of individuals were located independently of their will, since their processing was thus determined by law. The above circumstances would require the liable party to assume the greatest possible level of responsibility in ensuring the security of the personal data it has processed, and in the absence of such, at least active diligence and consistent implementation of obligations towards individuals who wish to find out whether or not their constitutional rights have been infringed due to shortcomings on the part of the liable party. At the same time, for the sake of transparency, the liable party must document the violation in the records of personal data processing activities (which the liable party keeps in accordance with Article 30 of the General Regulation), whereby the third party who has unauthorized access to the data is listed as a data user in the records of personal data processing activities.

83. At this point, the State Supervisor also refers to the statement of the liable party from the response to the information of …, in which the liable party wrote: “The principle of ignorantia iuris nocet (ignorance of the law harms) applies in law, which means that an individual or legal entity cannot rely on ignorance of the fact that it is entered in the register, nor on ignorance of the obligations arising from this entry. Individuals are therefore obliged to know and monitor their obligations regarding entry in individual records. Although we do not have a list of names of affected individuals, we estimate with a high degree of probability that these are obliged persons entered in the said records. "The stated statement by the obliged person indicates the obliged person's ignorance of the principles of the General Regulation. One of the fundamental principles of the General Regulation is the principle of transparency (from paragraph 1 of Article 5 of the General Regulation), which is, among other things, specified in the provisions of Articles 13 and 15 of the General Regulation. The stated provisions regulate the individual's right to information/notification and the right to access personal data and impose an obligation on the controller to inform the individual about the processing of his or her personal data (including when the data is obtained on the basis of the law directly from the individual - Article 13) and to confirm, upon request, whether personal data are being processed in relation to him or her, and, if so, to provide him or her with access to this data and to provide additional information (Article 15). These rights are not excluded even in cases where an individual is obliged to provide their data on the basis of applicable legislation. The obligor's claim that an individual does not have to notify whether they are registered with the obligor, because the individual is supposed to know this on their own (and if they do not know this, their ignorance of the law harms them), is therefore incorrect.

84. Since the obliged party stated during the inspection on … that it no longer has a copy of the data table affected in the security breach, dated …, and therefore the obliged party did not sufficiently document the facts regarding the security breach by … to be able to provide individuals with a definitive answer as to whether the individuals were affected in the security breach, I, the State Supervisor, reminded the obliged party of the duty to establish and obtain facts regarding the affected individuals in the inspection report. I reminded the obliged party that it is obliged to implement all technical and organizational measures and obtain all available information (including from other state authorities that may have additional information) in order to establish the facts regarding the personal data protection breach, which also includes obtaining information about which individuals were among those whose personal data were included in the personal data that was the subject of the attack. 

85. The State Supervisor then called on the liable party in the summons for written explanation, documentation and statement dated …, summons number 0612-91/2025/29 in point 3 to explain whether it had adopted technical and organizational measures and obtained all available information (including from other state authorities that may have additional information) in order to establish the facts regarding the security breach, which also includes obtaining information about which individuals were among those whose personal data were included in the personal data that were the subject of the security breach. The liable party was also called on to submit evidence regarding the measures taken. The liable party responded to the summons in point 3 of the response dated …, which does not list a single additional measure taken in order to obtain information about which individuals were among those whose personal data were included in the personal data that were the subject of the security breach. The liable party did not indicate such measures even in the response to the information on the findings dated ….

86. Taking into account the fact that the liable party did not implement any additional technical or organizational measures by … in order to establish the facts regarding which individuals were affected by the security breach, the State Supervisor further determined whether the liable party could implement such measures. 

87. Regarding the facts regarding which individuals were affected by the personal data security breach, the liable party stated during the inspection on …:

- Based on ….
- ….
- When asked by the State Supervisor whether the liable party could …. 

In the comments to the minutes, the liable party stated: ….

88. At the request of the State Supervisor, the liable party submitted the log records of the web server … for the period from … to …. The State Supervisor establishes that the content of the web server log record … dated … shows: 

Status …:
- ….
- In the context of web servers ….

Structure:
- ….
- …. 
- ….

No signs of …:
- ….
- ….
- ….

The State Supervisor establishes that the content of the web server log record dated … shows with certainty that the entire content of the table … as of … was shown to the person who unlawfully accessed the data of the person liable for the security breach and that the person became familiar with it. Based on the content of the web server log record, we can also establish that it is likely that the person also transferred the data to their control. 

89. Taking into account the above, the State Supervisor finds that the obliged party knew or should have known that the third party who accessed the data in table … in the security breach had been shown the personal data of all individuals included in table … on the day of the attack. The obliged party should therefore, in relation to each individual who contacted him with a question as to whether his personal data had been processed without authorisation, establish whether he had been entered in table … on the day …. If the obliged party had established that an individual had been entered in table … on the day …, he would be obliged to clearly answer this individual that his personal data had been shown to the third party in the security breach. 

90. If the obliged party no longer had a backup copy of the database for the day …, he would be obliged to check and implement all available technical and organisational measures (i) to restore the state of table … on that day in another way or (ii) to establish whether the individual had been entered in table … on that day. The taxpayer should at least:

a) examine all diary records or other technical/application/base records that the taxpayer has in connection with table … in order to establish the fact whether the individual was entered in table … on … or before that date; 
b) request … to examine all diary records or other technical/application/base records that the taxpayer has in connection with table … in order to establish the fact whether the individual was entered in table … on … or before that date, provide him with this information and take the information thus obtained into account in establishing the fact whether the individual was entered in table … on …. According to the taxpayer, table … is created by replicating table …, which is maintained by …. The taxpayer also explained that the data from table …. are not deleted. If the tables are replicated, it is therefore certain that if the individual was entered in table … on … or before that date, he was also entered in table … on ….;
c) examine all documentation relating to the individual held by the liable party, with the aim of establishing the fact whether the individual was entered in table … on …;
d) request … to examine all documentation relating to the individual held by …, with the aim of establishing the fact whether the individual was entered in table … on … or before that date, forward this data to him and take the data thus obtained into account in establishing the fact whether the individual was entered in table … on …;
e) request … to address a request to … in which … requests from …. the matter information on whether …. … has transmitted the individual’s data from … on … or before that date, in connection with the integration on the basis of which … enters the individual’s data obtained from … into table …, forward this data to him and take the data thus obtained into account in establishing the fact whether the individual was entered in table … on …. The liable party explained that … is connected to … in such a way that data on subjects from … is copied to … upon request, therefore, when determining whether an individual was entered in the table …, it is necessary to take into account the fact that the individual’s data was transmitted from … to … on a certain date.

91. In conclusion, the State Supervisory Authority finds that the liable party could and must implement additional technical and organizational measures (at least the measures from the previous point of this explanation) in order to determine whether their personal data were actually affected in relation to individuals who have addressed an explicit request to it for confirmation of whether their personal data were affected in a security breach, and must also adequately document these measures in accordance with the fifth paragraph of Article 33 of the General Regulation. 
92. Due to the identified irregularities, the liable party had to be ordered, on the basis of point 1 of the first paragraph of Article 29 of the ZVOP-2, point 1 of Article 32 of the ZIN and point (d) of the second paragraph of Article 58 of the General Regulation, to eliminate the identified irregularities and to harmonize the personal data processing activities with the provisions of the General Regulation, in the manner specified in point III of the operative part of this decision, namely within the time limit specified in point VII of the operative part of this decision.

Regarding the right of access pursuant to Article 15 of the General Regulation 

93. The State Supervisor establishes that the liable party received explicit requests for access to Article 15 of the General Regulation. The Obligor also received requests from individuals who did not explicitly state that they were requesting access under Article 15 of the General Regulation, but the request was clear from the text of their letter (they requested information on whether the security breach specifically concerns them, which means that they requested information on whether the person who unlawfully accessed the Obligor’s data in the security breach was a user of their personal data). The individuals whose requests are summarised in points 14 to 37 of this decision were therefore exercising their right to access personal data.

94. The right of an individual to access personal data is a fundamental human right, set out in the third paragraph of Article 38 of the Constitution of the Republic of Slovenia (Official Gazette of the Republic of Slovenia, No. 33/91-I, as amended), which stipulates that everyone has the right to access collected personal data relating to them. A similar provision is also contained in the Charter of Fundamental Rights of the European Union, which provides in Article 8(2) that everyone has the right of access to data collected about them. This right, known as the right of access of the data subject, is given concrete form in Article 15 of the General Regulation, which provides in its first paragraph that the data subject has the right to obtain from the controller 1) confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, 2) access to the personal data and 3) the following information:
(a) the purposes of the processing;
(b) the categories of personal data concerned;
(c) the users or categories of users to whom the personal data have been or will be disclosed, in particular users in third countries or international organisations;
(d) where possible, the envisaged period for which the personal data will be stored or, where that is not possible, the criteria used to determine that period;
(e) the existence of the right to obtain from the controller the rectification or erasure of personal data or the restriction of processing of personal data concerning the data subject, or the existence of the right to object to such processing;
(f) the right to lodge a complaint with a supervisory authority;
(g) where the personal data are not collected from the data subject, all available information as to their source;
(h) the existence of automated decision-making, including profiling referred to in Article 22(1) and (4), and at least in such cases, meaningful information on the reasons for it, as well as the significance and envisaged consequences of such processing for the data subject.

95. The data subject must therefore provide individuals who have exercised their right to access personal data with information about the users to whom personal data have been disclosed, including whether the individual who accessed the data in table … without authorisation on … accessed the individual’s personal data.

96. In accordance with point 9 of Article 4 of the General Regulation, a user means a natural or legal person, public authority, agency or other body to whom personal data have been disclosed, regardless of whether it is a third party or not. A user is therefore also a person who has unlawfully accessed personal data in the case of a security breach by the data subject.
97. In its response to the findings of …, the data subject stated that the term user (from Article 4 of the General Regulation) should be understood in the sense of a person or body to whom the controller or processor discloses personal data and that it does not initiate disclosure in cases of unlawful access to personal data. According to the data subject, this also follows from the Guidelines on personal data breaches of the EDPB (European Data Protection Board), formerly WP29, and Guidelines 9/2022 on personal data breach notification under the General Data Protection Regulation, which were allegedly issued by the IP (where, according to the data subject, the IP does not state that any unauthorised access should be recorded in the records of processing activities, but rather states that the controller may decide to document breaches within its records of processing activities, which it maintains in accordance with Article 30 of the General Data Protection Regulation), whereby the data subject does not refer to the place in the guidelines where the guidelines allegedly include the aforementioned interpretation of the term user. 
98. The National Supervisor, after reviewing the published guidelines of the European Data Protection Board, its predecessor, the Article 29 Working Party (WP29), and the guidelines of the Information Commissioner, finds that the following guidelines exist that correspond to the names of the guidelines referred to by the data subject:
- Guidelines 9/2022 on the notification of personal data breaches under the General Data Protection Regulation, adopted on 28 March 2023 by the European Data Protection Board (hereinafter: Guidelines 9/2022);
- Guidelines on personal data breach notification under Regulation 2016/679, adopted on 3 October 2017, as last revised and adopted on 6 February 2018, by the Article 29 Data Protection Working Party, guideline number WP250rev.01 (hereinafter: Guidelines WP250rev.01)
The National Supervisory Authority notes that the IP has not adopted the guidelines entitled “Guidelines 9/2022 on personal data breach notification under the General Data Protection Regulation”. 
The National Supervisor further notes that Guidelines 9/2022 state: “On 3 October 2017, the Article 29 Working Party adopted Guidelines on personal data breach notification under Regulation 2016/679 (WP250 rev.01)2, which were endorsed by the European Data Protection Board (hereinafter: the EDPB) at its first plenary session3. This document is a slightly updated version of these Guidelines. Any reference to the Article 29 Working Party Guidelines on personal data breach notification under Regulation 2016/679 (WP250 rev.01) should henceforth be understood as a reference to these EDPB Guidelines 9/2022.” Taking the above into account, the National Supervisor considered only Guidelines 9/2022 to be valid. 
99. Taking the above into account, I have reviewed Guidelines 9/2022 in order to determine whether they contain provisions relating to the concept of “user” from Article 4 of the General Regulation, in the content as stated by the liable party in the response to the information on the findings of …. I find that Guidelines 9/2022 do not contain such content, since they nowhere stipulate that the concept of user should be interpreted in the sense of a person or body to whom the controller or processor discloses personal data, whereby disclosure does not occur in cases of unlawful access to personal data.
100. I assume that the National Supervisor considered footnote number 47 on page 26 of Guidelines 9/2022 to be the relevant provision, which reads: “The controller may decide to document infringements within the framework of its records of processing activities, which it keeps in accordance with Article 30 of the General Data Protection Regulation. If the information relating to the breach is clearly identifiable as such and can be obtained upon request, a separate record is not required.” The aforementioned note refers to paragraph 122, which discusses the establishment of a register of breaches required under Article 33(5) of the GDPR. The National Supervisor notes that the fact that Guidelines 9/2022 do not provide that every unauthorised access should be recorded in the record of processing activities, but rather that the controller may decide to document breaches in the record of processing activities, does not mean that there is no obligation to list users in the record of personal data processing activities or that unauthorised third parties who unlawfully access the controller’s data do not have to be considered data users. The guidelines focus on the obligations under Articles 33 and 34 of the General Regulation (notification of personal data breaches) and do not comprehensively regulate the obligations of the controller in relation to keeping records of processing activities under Article 30 of the General Regulation.
101. Furthermore, the liable party stated that case law (e.g. I Up 420/2000) also clearly distinguishes between the controller of a personal data file, who is authorised to create and keep records, and the user, who merely uses the data. After reviewing the judgment I Up 420/2000, the State Supervisor notes that it is a judgment of the Supreme Court of 13 May 2004, i.e. from the period before the entry into force of the General Regulation. Therefore, the interpretation of the term "user" in the aforementioned judgment is not relevant for understanding the term "user" within the meaning of the General Regulation.
102. Taking into account the above, the State Supervisor concludes that the obliged entity's understanding of the term user is incorrect and that the term user must be understood as defined by the General Regulation, i.e. as a natural or legal person, public authority, agency or other body to whom personal data have been disclosed, regardless of whether it is a third party or not and regardless of the manner in which the data were disclosed (including cases where the data were disclosed due to unlawful conduct of a third party). It follows quite clearly from the aforementioned definition of the term user that it is essential and at the same time sufficient for its definition that personal data have been disclosed to it and that the manner in which they were disclosed is not relevant. The obliged entity's statements that an entity to whom personal data have been disclosed can be considered a user only on the additional condition that the controller or processor disclosed these data to it, or even that it is a user only if the controller or processor discloses the personal data to it knowingly, intentionally and lawfully, have no basis in the provisions of the General Regulation.

103. Guidelines 01/2022 on the rights of data subjects – right of access (hereinafter: the Guidelines) state: “In addition to access to personal data, the controller must also provide additional information on the processing and the rights of individuals. This may be based on information already collected in the records of processing activities (Article 30 of the GDPR) and the personal data protection statement (Articles 13 and 14 of the GDPR). However, this general information may need to be updated depending on the moment of the request or adapted to reflect the processing operations carried out in relation to the person making the request.” The same follows from point 113 of the Guidelines, which states: “Other types of information, such as information on users, types and source of data, may vary depending on who makes the request and its scope. In the context of a request for access pursuant to Article 15, all information on the processing available to the controller must therefore be updated and adapted to the processing operations actually carried out in relation to the individual making the request”. Furthermore, with regard to the identification of users, point 117 of the Guidelines states: “Unless the individual has chosen otherwise, the controller must, in accordance with Article 15, name the actual users, unless the identification of those users is not possible or unless that controller demonstrates that the requests for access are manifestly unfounded or excessive within the meaning of Article 12(5) of the GDPR”.
104. It follows from the above that the right of access under Article 15 of the GDPR is a right which requires an individualised assessment and specification of information in relation to the actual processing of the personal data of the individual at the time of the decision on the request, and not merely the provision of general or pre-prepared information.
105. In order to be able to decide legally and substantively correctly on the individual's request under Article 15 of the General Regulation, the data subject must therefore update and adapt the information on the processing of the individual's personal data, which also includes precise information on the users of this data. In the specific case, this means that it must determine separately for each individual whether the third party who, in the context of the security breach, unlawfully accessed the personal data in table ... was a user of the individual's personal data. Without such a determination, the data subject cannot provide the individual with complete and true information on the users of his or her personal data, which would substantially impair the right to access.
106. In order to determine the above, the data subject must implement available technical and organisational measures (at least the measures referred to in point III of the operative part of this decision). As already explained in point 82 of this decision, establishing and obtaining facts about whether the person who has unauthorized access to personal data in table … is a user of the individual's personal data is also required from the perspective of the principle of accountability referred to in the second paragraph of Article 5 of the General Regulation in conjunction with the principle of legality, fairness and transparency referred to in point (a) of the first paragraph of Article 5 of the General Regulation.
107. The principle of transparency does not mean merely formal notification of individuals, but requires that the controller has factual, accurate and verified information on the processing of personal data and that it is also able to provide this information to the individual. The controller must act fairly and honestly not only in cases of regular, lawful processing of personal data, but especially in the event of a personal data breach, in particular when this has occurred due to shortcomings on its part.
108. In such circumstances, the controller is obliged to do everything that is reasonable and objectively within its power to ensure that the affected individuals can effectively exercise the right of access under Article 15 of the General Regulation. Allowing the controller to act in such a way that it would rely on the fact that it does not have the requested information because it has not taken the necessary steps to obtain it would constitute a breach of the right of access that the individual has under the General Regulation. 
109. In the case at hand, it is undisputed that the liable party could have implemented additional technical and organizational measures to determine whether an unauthorized third party had actually become a user of the personal data of individuals, but did not implement these measures. Since the liable party did not implement these measures, the liable party had to be ordered, on the basis of point 1 of the first paragraph of Article 29 of the ZVOP-2, the first paragraph of Article 32 of the ZIN and point (d) of the second paragraph of Article 58 of the General Regulation, to eliminate the identified irregularities and to align the personal data processing operations with the provisions of the General Regulation in the manner specified in point III. of the operative part of this decision, namely within the time limit specified in point VII. of the operative part of this decision.

Point IV. operative part 

110. Article 17 of the GDPR provides that the data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following reasons applies:
(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

(b) the data subject withdraws consent to the processing pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) and where there is no other legal ground for the processing;
(c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);
(d) the personal data have been processed unlawfully;
(e) the personal data must be erased for compliance with a legal obligation under Union law or the law of a Member State to which the controller is subject;
(f) the personal data were collected in connection with the offering of information society services referred to in Article 8(1).

111. If the controller does not grant the individual’s request for erasure, it must, in accordance with Article 13 of the ZVOP-2, issue a decision which, in addition to the elements laid down in the law governing general administrative procedure, also contains the elements laid down in the ZVOP-2. The ZVOP-2 provides that where the individual’s request is not granted, the decision must state in the legal text the right to lodge a complaint with a supervisory authority within 15 days of the notification of the decision in the case, pursuant to the provisions of point f) of the first paragraph of Article 15 of the General Regulation. Where the controller grants the individual’s request, it shall not issue a separate decision, but shall make an official note thereof and inform the individual of the decision.

112. The State Supervisor, with regard to the request …, summarized in point 21 of this decision, finds that the request constitutes a request under Article 17 of the General Regulation and that the liable party has not decided on the request within the deadline set out in Article 12 of the General Regulation. The liable party must therefore decide on the request … in accordance with the provisions of Article 13 of the ZVOP-2 in conjunction with Article 17 of the General Regulation. The State Supervisor, with regard to the request …, summarized in point 36 of this decision, finds that the liable party rejected the request for deletion, but did not issue a decision, in accordance with the requirements of Article 13 of the ZVOP-2. The liable party must therefore decide on the request … in accordance with the provisions of Article 13 of the ZVOP-2 in conjunction with Article 17 of the General Regulation.

113. Due to the identified irregularities, the liable party had to be ordered, on the basis of point 1 of the first paragraph of Article 29 of the ZVOP-2, point 1 of Article 32 of the ZIN and point (d) of the second paragraph of Article 58 of the General Regulation, to eliminate the identified irregularities and to harmonize the personal data processing activities with the provisions of the General Regulation, in the manner specified in point IV of the operative part of this decision, namely within the period specified in point VIII of the operative part of this decision.

Point IX of the operative part

114. The order in point IX of the operative part of this decision that, after implementing the measures referred to in points I, II, III and IV of the operative part of this decision, the liable party is obliged to notify the IP in writing within 5 (five) days after their implementation is based on the provision of the fifth paragraph of Article 29 of the ZIN, which stipulates that the liable party must immediately notify the inspector of the eliminated irregularities.

Regarding the issuance of a partial decision

115. The ZUP stipulates in Article 219 that when a matter can be decided in parts, but individual parts are suitable for a decision, the competent authority may issue a decision only on these parts (partial decision). The State Supervisor finds that in the inspection procedure in question, the obliged party must first be ordered to take the measure referred to in points II. and III. of the operative part of this decision in order for the obliged party to carry out the identification of individuals and then to carry out technical and organizational measures in order to obtain information regarding the question of whether the individual's data was affected by the security breach (i.e. the question of whether the person who unlawfully accessed the data in table ... is a user of the individual's personal data). When the obliged party has carried out the measures referred to in points II. and III. of this ruling and provided that the liable party does not meet the requirements of Article 34 of the General Regulation and Article 15 of the General Regulation after the implementation of these measures, the IP will issue a supplementary decision in which it will order measures for the purpose of implementing the provisions of Articles 15 and 34 of the General Regulation. 

***

Based on Article 118 of the ZUP, the decision shall decide on the costs of the procedure. Since no special costs were incurred in this procedure, it is so decided in point X of the ruling. 

This decision is issued ex officio and is free of fees pursuant to Article 22 of the Administrative Fees Act (Official Gazette of the Republic of Slovenia, No. 106/10 – UPB5, 14/15 – ZUUJFO, 84/15 – ZZelP-J and 32/16). 

Instructions on legal remedies: 
This decision is final in administrative proceedings. According to the provisions of Article 54 of the ZVOP-2, no appeal is permitted against it, but an administrative dispute is possible by filing a lawsuit with the Administrative Court of the Republic of Slovenia, Fajfarjeva 33, 1000 Ljubljana, within 30 days of receiving this decision. The lawsuit shall be filed with the competent court directly in writing or sent to it by post. The lawsuit in two copies must be accompanied by this decision in the original or an uncertified copy. 

Information Commissioner:
…
State Supervisor for Personal Data Protection

Serve:
- ... (in accordance with Article 85a of the ZUP)