{"id":34169,"date":"2025-05-29T15:02:30","date_gmt":"2025-05-29T15:02:30","guid":{"rendered":"https:\/\/www.digife.it\/?p=34169"},"modified":"2025-05-29T15:02:30","modified_gmt":"2025-05-29T15:02:30","slug":"guarantors-provision-penalty-for-use-of-obsolete-and-outdated-systems","status":"publish","type":"post","link":"https:\/\/www.digife.it\/en\/guarantors-provision-penalty-for-use-of-obsolete-and-outdated-systems\/","title":{"rendered":"Provision of the Guarantor: Sanction for use of obsolete and outdated systems"},"content":{"rendered":"<p data-start=\"396\" data-end=\"773\">With the <strong data-start=\"403\" data-end=\"446\">provision no. 237 of 24 April 2024<\/strong> (<a class=\"cursor-pointer\" target=\"_new\" rel=\"noopener\" data-start=\"448\" data-end=\"546\">web doc. n. 10025835<\/a>), the Guarantor for the Protection of Personal Data has reiterated a fundamental principle for those who manage personal data online: <strong data-start=\"675\" data-end=\"773\">Keeping your IT systems up to date is a legal requirement, not just good IT practice.<\/strong><\/p>\n<p data-start=\"775\" data-end=\"1249\">The case concerns a company that, following a complaint about unwanted emails, was the subject of investigations that highlighted the prolonged use of a <strong data-start=\"943\" data-end=\"973\">Outdated and vulnerable CMS<\/strong>, despite security updates having been available for months. Technical analysis has confirmed the presence of <strong data-start=\"1094\" data-end=\"1141\">critical vulnerabilities (CVSS up to 9.8\/10)<\/strong> which could have exposed the data to unauthorized processing, illicit access or cyber attacks.<\/p>\n<h3 data-start=\"1251\" data-end=\"1283\">What the Guarantor has established<\/h3>\n<p data-start=\"1285\" data-end=\"1408\">The Guarantor has detected the <strong data-start=\"1311\" data-end=\"1363\">breach of data protection obligations<\/strong> (articles 5, 24 and 32 GDPR), underlining how:<\/p>\n<ul data-start=\"1410\" data-end=\"1577\">\n<li data-start=\"1410\" data-end=\"1460\">\n<p data-start=\"1412\" data-end=\"1460\">failure to adopt adequate technical measures;<\/p>\n<\/li>\n<li data-start=\"1461\" data-end=\"1509\">\n<p data-start=\"1463\" data-end=\"1509\">continued use of out-of-date software;<\/p>\n<\/li>\n<li data-start=\"1510\" data-end=\"1577\">\n<p data-start=\"1512\" data-end=\"1577\">the inability to detect unauthorized access in a timely manner;<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1579\" data-end=\"1789\">have represented a <strong data-start=\"1604\" data-end=\"1627\">serious breach<\/strong>. A sentence was then inflicted <strong data-start=\"1657\" data-end=\"1699\">administrative fine of 30,000 euros<\/strong>, to which is added the obligation to communicate the corrective measures adopted within 30 days.<\/p>\n<h3 data-start=\"1791\" data-end=\"1828\">The message for all companies<\/h3>\n<p data-start=\"1830\" data-end=\"1976\">This case highlights an aspect that is often underestimated: <strong data-start=\"1889\" data-end=\"1975\">Cyber security is not only a technical responsibility, but also a legal one<\/strong>.<\/p>\n<p data-start=\"1978\" data-end=\"2046\">Anyone who manages websites, e-commerce, newsletters or CRM has the duty to:<\/p>\n<ul data-start=\"2048\" data-end=\"2337\">\n<li data-start=\"2048\" data-end=\"2154\">\n<p data-start=\"2050\" data-end=\"2154\"><strong data-start=\"2050\" data-end=\"2107\">Check for available updates regularly<\/strong> for CMS, plugins, modules and management systems;<\/p>\n<\/li>\n<li data-start=\"2155\" data-end=\"2206\">\n<p data-start=\"2157\" data-end=\"2206\"><strong data-start=\"2157\" data-end=\"2205\">apply security patches promptly<\/strong>;<\/p>\n<\/li>\n<li data-start=\"2207\" data-end=\"2270\">\n<p data-start=\"2209\" data-end=\"2270\"><strong data-start=\"2209\" data-end=\"2269\">actively monitor traffic and anomalous access<\/strong>;<\/p>\n<\/li>\n<li data-start=\"2271\" data-end=\"2337\">\n<p data-start=\"2273\" data-end=\"2337\"><strong data-start=\"2273\" data-end=\"2315\">document risk assessments<\/strong> and the measures adopted.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2339\" data-end=\"2481\">Failure to do so may result in <strong data-start=\"2364\" data-end=\"2395\">heavy economic sanctions<\/strong>, but above all it can compromise user trust and company reputation.<\/p>\n<hr data-start=\"2483\" data-end=\"2486\" \/>\n<p data-start=\"2488\" data-end=\"2641\">\ud83d\udd0d <em data-start=\"2491\" data-end=\"2641\">Want to know if your site is up to date and secure? Let&#039;s evaluate together the status of your CMS, your extensions and the security practices in use.<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>With provision no. 237 of 24 April 2024 (web doc. no. 10025835), the Guarantor for the Protection of Personal Data reiterated a fundamental principle for those who manage data\u2026<\/p>","protected":false},"author":4,"featured_media":33989,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-34169","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-curiosita-web"},"_links":{"self":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/34169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/comments?post=34169"}],"version-history":[{"count":1,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/34169\/revisions"}],"predecessor-version":[{"id":34170,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/34169\/revisions\/34170"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/media\/33989"}],"wp:attachment":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/media?parent=34169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/categories?post=34169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/tags?post=34169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}