Back to Feed
PolicyOct 6, 2026

UODO (Poland) - DKN.5131.24.2025

Poland's UODO fines court bailiff for GDPR violations regarding DPO.

Summary

Poland's data protection authority (UODO) has fined a court bailiff PLN 15,500 (€3,500) for violating GDPR. The violations included failing to publish and communicate the data protection officer's contact details to the UODO, and a conflict of interest where the bailiff also served as the DPO, undermining their independence.

Full text

Help UODO (Poland) - DKN.5131.24.2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 13:08, 6 October 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators209 editsTag: Visual edit← Older edit Latest revision as of 13:16, 6 October 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators209 editsTag: Visual edit Line 98: Line 98: First, the DPA concluded that the controller had failed to publish the contact details of the data protection officer and communicate them to the DPA as required by [[Article 37 GDPR|Article 37(7) GDPR]]. It pointed out that court bailiffs are public officials who execute judgments and perform their duties under the surveillance of a district court. In addition, they manage individual bailiff's offices. As controllers, bailiffs are obligated to appoint a data protection officer. First, the DPA concluded that the controller had failed to publish the contact details of the data protection officer and communicate them to the DPA as required by [[Article 37 GDPR|Article 37(7) GDPR]]. It pointed out that court bailiffs are public officials who execute judgments and perform their duties under the surveillance of a district court. In addition, they manage individual bailiff's offices. As controllers, bailiffs are obligated to appoint a data protection officer. Second, the DPA held that the controller's tasks and duties as both a bailiff and a data protection officer had resulted in a conflict of interests within the meaning of [[Article 38 GDPR|Article 38(6) GDPR]]. In the present case, the controller made decisions as a bailiff that must subsequently be subject to the data protection officer's assessment. This undermined the controller's ability to effectively carry out their tasks as a data protection officer. The controller had the highest-level position in the organisational hierarchy of the bailiff's office and therefore lacked an independent status within the organisation and the freedom to make autonomous decisions as a data protection officer.Second, the DPA held that the controller's tasks and duties as both a bailiff and a data protection officer had resulted in a conflict of interests within the meaning of [[Article 38 GDPR|Article 38(6) GDPR]]. In the present case, the controller made decisions as a bailiff that must subsequently be subject to the data protection officer's assessment. This undermined the controller's ability to effectively carry out their tasks as a data protection officer. The controller had the highest-level position in the organisational hierarchy of the bailiff's office and therefore lacked an independent status within the organisation as well as the freedom to make autonomous decisions as a data protection officer. Latest revision as of 13:16, 6 October 2026 UODO - DKN.5131.24.2025 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 37(7) GDPR Article 38(6) GDPR Type: Investigation Outcome: n/a Started: 15.12.2025 Decided: 29.07.2026 Published: 25.09.2026 Fine: n/a Parties: n/a National Case Number/Name: DKN.5131.24.2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Polish Original Source: UODO (in PL) Initial Contributor: av The DPA fined a court bailiff PLN 15,500 (€3,500) for a failure to communicate the contact details of the data protection officer to the DPA and a conflict of interests with data protection officer's other tasks and duties. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A bailiff appointed by a district court (the controller) notified the DPA of a data breach in April 2023. According to the data breach notification, the controller also held the position of data protection officer within the bailiff's office from January 2020 to September 2025. However, the contact details of the data protection officer had not been published or communicated to the DPA. The DPA initiated an investigation regarding the appointment and the status of the data protection officer. The controller argued that it had not been obligated to appoint a data protection officer but had instead carried out the data protection officer's tasks on a voluntary basis. Holding The DPA held that the controller had violated Articles 37(7) and 38(6) GDPR. It issued the controller a fine of PLN 3,500 (€800) for the former and PLN 12,000 (€2,700) for the latter GDPR infringement. The DPA imposed two separate fines on the controller as it considered the violations at issue to constitute two independent acts by the controller. First, the DPA concluded that the controller had failed to publish the contact details of the data protection officer and communicate them to the DPA as required by Article 37(7) GDPR. It pointed out that court bailiffs are public officials who execute judgments and perform their duties under the surveillance of a district court. In addition, they manage individual bailiff's offices. As controllers, bailiffs are obligated to appoint a data protection officer. Second, the DPA held that the controller's tasks and duties as both a bailiff and a data protection officer had resulted in a conflict of interests within the meaning of Article 38(6) GDPR. In the present case, the controller made decisions as a bailiff that must subsequently be subject to the data protection officer's assessment. This undermined the controller's ability to effectively carry out their tasks as a data protection officer. The controller had the highest-level position in the organisational hierarchy of the bailiff's office and therefore lacked an independent status within the organisation as well as the freedom to make autonomous decisions as a data protection officer. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details. Emblem of the Republic of Poland Office for Personal Data Protection Decisions Portal Decision logo Warsaw, July 29, 2026 not final Decision DKN.5131.24.2025 Pursuant to Article 104 § 1 of the Act of June 14, 1960, Code of Administrative Procedure (Journal of Laws of 2025, item 1691), in conjunction with Article 7(1) and (2), Article 10, Article 60, Article 102(1)(1) and (3) of the Act of May 10, 2018, on data protection (Journal of Laws of 2019, Item 1781, as amended), hereinafter referred to as: “the Act of May 10, 2018,” and Art 57(1)(a) and (h), Art 58(2)(i), Art 83(1)–(3), Article 83(4)(a) in conjunction with Article 37(7) and Article 38(6) of Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119 of May 4, 2016, p. 1; OJ EU L 127 of May 23, 2018, p. 2, and Official Journal of the EU L 74 of March 4, 2021, p. 35), hereinafter referred to as “Regulation 2016/679,” following an ex officio administrative proceeding concerning a violation by the Court Bailiff at the District Court in B., H. K., conducting (…) in B. (ul. (…), (…)-(…) B.), of the provisions on data protection, the President of the Personal Data Protection Office: I. finding that the Court Bailiff at the District Court in B. H. K. violated Article 37(7) of Regulation 2016/679 in conjunction with Article 10 of the Act of May 10, 2018, consisting of a failure to notify the supervisory authority of the appointment of a data protection officer within 14 days of the date of such appointment, imposes on the Court Enforcement Officer at the District Court in B. H. K. an administrative fine in the amount of 3,500 PLN (in words: three thousand five

Entities

UODO (vendor)