[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzpj6j3UMum00c_1UWRWq9USBoxH5v6fiQR4EGpOVjMo":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"8f4f43b4-3031-479d-90fc-542bf960f112","UODO (Poland) - DKN.5131.12.2022","uodo-poland-dkn-5131-12-2022-afb2ee","← Older revision Revision as of 07:50, 21 July 2026 Line 78: Line 78: The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022 The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. === Holding === === Holding === The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated [[Article 28 GDPR#1|Article 28(1) GDPR]]: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated [[Article 28 GDPR#1|Article 28(1) GDPR]]: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and (2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. Second, the DPA found that the controller had infringed [[Article 24 GDPR|Articles 24(1)]], [[Article 25 GDPR|25(1)]], and [[Article 32 GDPR|32(1)]] and [[Article 32 GDPR|32(2) GDPR]] by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of [[Article 35 GDPR#1|Article 35(1) GDPR]] in conjunction with [[Article 35 GDPR#3|Article 35(3) GDPR]] due to the controller’s failure to conduct a data protection impact assessment. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in [[Article 5 GDPR|Articles 5(1)(f)]] and [[Article 5 GDPR|5(2) GDPR]] as well. Finally, the DPA found a violation of [[Article 35 GDPR#1|Article 35(1) GDPR]] in conjunction with [[Article 35 GDPR#3|Article 35(3) GDPR]] due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with [[Article 28 GDPR#3c|Article 28(3)(c) GDPR]]. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated [[Article 32 GDPR|Articles 32(1)]] and [[Article 32 GDPR|32(2) GDPR]] in conjunction with [[Article 28 GDPR#3c|Article 28(3)(c) GDPR]]. == Comment == == Comment ==","Poland's Data Protection Authority (UODO) issued a reprimand to a provincial specialist hospital and its external service provider following a December 2021 email hack. The compromised account exposed sensitive patient data, including names, addresses, phone numbers, vaccination details, and national identification numbers of approximately 200 individuals. The hospital failed to verify its processor's security measures and implement adequate technical and organizational safeguards for its email system. The processor also failed to conduct a risk analysis and implement sufficient security measures.","Polish DPA reprimands hospital and processor for GDPR violations after email hack.","Help UODO (Poland) - DKN.5131.12.2022: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 07:47, 21 July 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators85 edits Tag: submission [1.0] Latest revision as of 07:50, 21 July 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators85 editsTag: Visual edit Line 78: Line 78: The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor).The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. === Holding ====== Holding === The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated [[Article 28 GDPR#1|Article 28(1) GDPR]]: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures.The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated [[Article 28 GDPR#1|Article 28(1) GDPR]]: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and (2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. Second, the DPA found that the controller had infringed [[Article 24 GDPR|Articles 24(1)]], [[Article 25 GDPR|25(1)]], and [[Article 32 GDPR|32(1)]] and [[Article 32 GDPR|32(2) GDPR]] by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in Articles 5(1)(f) and 5(2) GDPR as well. Finally, the DPA found a violation of [[Article 35 GDPR#1|Article 35(1) GDPR]] in conjunction with [[Article 35 GDPR#3|Article 35(3) GDPR]] due to the controller’s failure to conduct a data protection impact assessment. As a consequence of the previous violations, the controller had infringed the principles of integrity, confidentiality and accountability laid down in [[Article 5 GDPR|Articles 5(1)(f)]] and [[Article 5 GDPR|5(2) GDPR]] as well. Finally, the DPA found a violation of [[Article 35 GDPR#1|Article 35(1) GDPR]] in conjunction with [[Article 35 GDPR#3|Article 35(3) GDPR]] due to the controller’s failure to conduct a data protection impact assessment. The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated Articles 32(1) and 32(2) GDPR in conjunction with [[Article 28 GDPR#3c|Article 28(3)(c) GDPR]].The DPA also reprimanded the processor for the failure to implement appropriate technical and organisational measures to ensure the security of processing – the processor had failed to conduct a risk analysis and to implement adequate security measures, such as blocking a user’s account after a certain amount of login attempts. The DPA held that the processor had violated [[Article 32 GDPR|Articles 32(1)]] and [[Article 32 GDPR|32(2) GDPR]] in conjunction with [[Article 28 GDPR#3c|Article 28(3)(c) GDPR]]. == Comment ==== Comment == Latest revision as of 07:50, 21 July 2026 UODO - DKN.5131.12.2022 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 5(1)(f) GDPR Article 5(2) GDPR Article 24(1) GDPR Article 25(1) GDPR Article 28(1) GDPR Article 32(1) GDPR Article 35(1) GDPR Type: Investigation Outcome: Violation Found Started: 11.03.2022 Decided: 11.06.2026 Published: 14.07.2026 Fine: n\u002Fa Parties: n\u002Fa National Case Number\u002FName: DKN.5131.12.2022 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Polish Original Source: UODO (in PL) Initial Contributor: av The DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses, phone numbers, vaccination appointments, and national identification numbers of approximately 200 patients (the data subjects). The email account was hosted on the servers of an external service provider (the processor). The controller notified the supervisory authority of this data breach at the end of December 2021. The DPA started an investigation regarding potential GDPR infringements by the controller and the processor in March 2022. Holding The DPA issued the controller a reprimand for multiple GDPR violations. First, it held that the controller had violated Article 28(1) GDPR: while the controller had concluded a data processing agreement with the processor, it had failed to verify whether the processor provided sufficient guarantees to implement appropriate technical and organisational measures. Second, the DPA found that the controller had infringed Articles 24(1), 25(1), and 32(1) and 32(2) GDPR by failing to implement appropriate technical and organisational measures to ensure the security of processing via the email system. The DPA took into account that the controller had not taken any measures to minimise the risks identified. In addition, the DPA pointed out that the breach involved sensitive health data, and the passwords used by the controller did not meet the usual security requirements. As a consequence of the previous violations, the controller had infringed the principles of i","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.12.2022&diff=52415&oldid=52414","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F7\u002F7b\u002FLogoPL.png","2026-07-21T07:50:54+00:00","2026-07-21T08:00:23.500636+00:00",7,[18,21],{"name":19,"type":20},"UODO","vendor",{"name":22,"type":23},"email account","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]