Back to Feed
PolicySep 30, 2026

UODO (Poland) - DKE.561.7.2026

UODO (Poland) fines a company PLN 31,507 for failing to provide access to data.

Summary

Poland's UODO has fined a company PLN 31,507 (€7,200) for failing to provide the data protection authority with necessary access to personal data and other information. The investigation stemmed from a prior case where the company collected personal data but did not disclose its identity or contact information on its websites. Despite multiple attempts to contact the controller, the DPA initiated proceedings, leading to the fine for violating GDPR Articles 58(1)(a) and 58(1)(e).

Full text

Help UODO (Poland) - DKE.561.7.2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 10:57, 29 September 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators199 edits Tag: Visual edit← Older edit Latest revision as of 06:39, 30 September 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators199 editsTag: Visual edit Line 32: Line 32: |GDPR_Article_1=Article 32(1) GDPR|GDPR_Article_1=Article 58 GDPR |GDPR_Article_Link_1=Article 32 GDPR#1|GDPR_Article_Link_1=Article 58 GDPR#1 Latest revision as of 06:39, 30 September 2026 UODO - DKE.561.7.2026 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 58 GDPR Type: Investigation Outcome: n/a Started: 15.06.2026 Decided: 01.09.2026 Published: 28.09.2026 Fine: n/a Parties: n/a National Case Number/Name: DKE.561.7.2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): [[:Category:|]] [[Category:]] Original Source: UODO (in ) Initial Contributor: av The DPA fined a company PLN 31,507 (€7,200) for the failure to provide the DPA access to personal data and other information necessary for the performance of its tasks. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA launched an investigation into two websites operated by the controller under case number DKN.5101.8.2025. The controller collected the names and the occupations of individuals (the data subjects) and had not disclosed its identity and contact information on the websites. The DPA requested the controller to provide information on the processing operations pursuant to Articles 58(1)(a) and 58(1)(e) GDPR. It attempted to contact the controller by sending it a letter on 15 April, an email on 15 May, and another email on 5 June. The DPA also called the business owner's contact number on 10 and 12 June, but the number was unavailable. Due to the unsuccessful attempts to contact the controller in connection with the proceedings in case DKN.5101.8.2025, the DPA initiated the administrative proceedings at issue against the controller. The controller was notified of this on June 15. The controller did not submit any additional explanations regarding the previous case, nor did it provide the data necessary to determine the basis for calculating the administrative fine in the present proceedings. Holding The DPA held that the controller had failed to provide the DPA access to personal data and other information it required for the performance of its tasks and issued the controller a fine of PLN 31,507 (€7,200). It found that the controller had violated Articles 58(1)(a) and 58(1)(e) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the original. Please refer to the original for more details. https://uodo.neurodoc.pl/document/urn:ndoc:gov:pl:uodo:2026:dke_561_7/content September 29, 2026, 6:59 a.m. NOT FINAL Warsaw, September 1, 2026 Decision DKE.561.7.2026 Pursuant to Art. 104 § 1 of the Act of June 14, 1960—Code of Administrative Procedure [1] (hereinafter referred to as the “Code of Administrative Procedure”) in conjunction with Article 7(1) and (2), Article 60, and Article 101 of the Act of May 10, 2018, on data protection [2] (hereinafter referred to as “PDPA”), as well as pursuant to Article 57(1)(a) and (h), Article 58(2)(i), Article 83(1)-(2), and Article 83(5)(e) in conjunction with Article 58(1)(a) and (e) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [3] (hereinafter referred to as “Regulation 2016/679”), following an ex officio administrative proceeding concerning the imposition of an administrative fine on Mr. M. T., conducting business activity under the name “C. (…)” (formerly “D. (…)”) (ul. (…), (…)-(…) Z.), the President of the Personal Data Protection Office (hereinafter referred to as “the President of the PDPA” or “the supervisory authority”): finding that Mr. M. T., conducting business under the name “C. (…),” of Article 58(1)(a) and (e) of Regulation 2016/679, consisting of a failure to provide access to the personal data and information necessary for the President of the UODO to perform his duties in the proceedings bearing reference number DKN.5101.8.2025.(…), imposes an administrative fine on him in the amount of 31,507 PLN (in words: thirty-one thousand five hundred seven zlotys). Decision DKE.561.7.2026 The website2 from 19 https://uodo.neurodoc.pl/document/urn:ndoc:gov:pl:uodo:2026:dke_561_7/content September 29, 2026, 6:59 a.m. Statement of Reasons I. Facts The President of the Personal Data Protection Office (UODO) received information indicating possible irregularities related to the operation of the website (…) and the associated website (…), which are used for data processing of individuals (…) and individuals (…). The report received by the President of the UODO indicated that the aforementioned websites were used for the processing of personal data regarding: first name, last name, and specific occupation in connection with misleadinginformation (occupation, contact details, location and manner of conducting professional practice) and articles suggesting that the person in question was their author. The President of the UODO also learned that both the website (…) and the website (…) failed to disclose the identity and contact information of the controller, which prevented the individuals whose data was being processed from effectively exercising their rights regarding privacy and personal data protection. The above information prompted the President of the UODO to initiate an investigation under case number DKN. 5101.8.2025.(…). The findings of the President of the Personal Data Protection Office (UODO) indicated that the operations of the websites (…) and (…), which were the subject of the reported irregularities, are linked to the business activities conducted by Mr. M. T. under the name “D. (…)” (currently: “C. (…)”). In view of the above, by a letter dated February 3, 2025, addressed to the service address disclosed in the Central Register and Information on Business Activity (hereinafter referred to as “CE-IDG”), i.e., (…), (…)-(…) Z., the President of the Personal Data Protection Office (UODO) notified Mr. M. T., conducting business under the name “D. (…)” (currently: “C. (…)”) (hereinafter referred to as the “Party,” “Controller,” “Entrepreneur”) that it had obtained the information referred to in point 1 of the preamble and informed him of the investigative proceedings conducted under case no. DKN.5101.8.2025.(…). The supervisory authority, acting pursuant to Article 58(1)( (a) and (e) of Regulation 2016/679, also requested the Party to provide explanations by answering the questions detailed in the letter, including, among other things, identifying the controller of the websites (…) and (…). In a letter dated February 26, 2025, the Party responded to the supervisory authority’s request. In its explanations, the Business confirmed, among other things, that it is the controller of the personal data processed through the website (…), and also addressed the remaining questions posed by the President of the Personal Data Protection Office (UODO). Decision DKE.561.7.2026 The website3 from 19 https://uodo.neurodoc.pl/document/urn:ndoc:gov:pl:uodo:2026:dke_561_7/content September 29, 2026, 6:59 a.m. The explanations provided by the Party proved insufficient; consequently, the President of the Personal Data Protection Office (UODO) issued further

Entities

UODO (vendor)