UODO (Poland) - DKN.5131.24.2025
Poland's DPA fines a court bailiff €3,500 for failing to notify DPO contact details and for conflict of interest.
Summary
Poland's Data Protection Authority (UODO) has fined a court bailiff PLN 15,500 (approximately €3,500) for two GDPR violations. The bailiff failed to communicate the contact details of its Data Protection Officer (DPO) to the DPA and was also found to have a conflict of interest due to performing both bailiff and DPO duties. The DPA imposed separate fines for each violation, totaling PLN 15,500.
Full text
Help UODO (Poland) - DKN.5131.24.2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 06:52, 7 October 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators214 editsTag: Visual edit← Older edit Latest revision as of 12:18, 7 October 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators606 editsm Tag: Visual edit Line 84: Line 84: }}}} The DPA fined a court bailiff PLN 15,500 (€3,500) for a failure to communicate the contact details of its data protection officer to the DPA. The DPA also found that the data protection officer had a conflict of interests with its other tasks and duties.The DPA fined a court bailiff PLN 15,500 (€3,500) for a failure to communicate the contact details of its data protection officer to the DPA. The DPA also found that the data protection officer had a conflict of interests with their other tasks and duties. == English Summary ==== English Summary == Latest revision as of 12:18, 7 October 2026 UODO - DKN.5131.24.2025 Authority: UODO (Poland) Jurisdiction: Poland Relevant Law: Article 37(7) GDPR Article 38(6) GDPR Type: Investigation Outcome: n/a Started: 15.12.2025 Decided: 29.07.2026 Published: 25.09.2026 Fine: n/a Parties: n/a National Case Number/Name: DKN.5131.24.2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Polish Original Source: UODO (in PL) Initial Contributor: av The DPA fined a court bailiff PLN 15,500 (€3,500) for a failure to communicate the contact details of its data protection officer to the DPA. The DPA also found that the data protection officer had a conflict of interests with their other tasks and duties. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A bailiff (the controller) appointed by a district court notified the DPA of a data breach in April 2023. According to the data breach notification, the controller also held the position of data protection officer within the bailiff's office from January 2020 to September 2025. However, the contact details of the data protection officer had not been published or communicated to the DPA. The DPA initiated an investigation regarding the appointment and the status of the data protection officer. The controller argued that it had not been obligated to appoint a data protection officer but had instead carried out the data protection officer's tasks on a voluntary basis. Holding The DPA held that the controller had violated Articles 37(7) and 38(6) GDPR. It issued the controller a fine of PLN 3,500 (€800) for the former and PLN 12,000 (€2,700) for the latter GDPR infringement. The DPA imposed two separate fines on the controller as it considered the violations at issue to constitute two independent acts by the controller. First, the DPA concluded that the controller had failed to publish the contact details of the data protection officer and communicate them to the DPA as required by Article 37(7) GDPR. It pointed out that court bailiffs are public officials who execute judgments and perform their duties under the surveillance of a district court. In addition, they manage individual bailiff's offices. As controllers, bailiffs are obligated to appoint a data protection officer. Second, the DPA held that the controller's tasks and duties as both a bailiff and a data protection officer had resulted in a conflict of interests within the meaning of Article 38(6) GDPR. In the present case, the controller made decisions as a bailiff that must subsequently be subject to the data protection officer's assessment. This undermined the controller's ability to effectively carry out their tasks as a data protection officer. The controller had the highest-level position in the organisational hierarchy of the bailiff's office and therefore lacked an independent status within the organisation as well as the freedom to make autonomous decisions as a data protection officer. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Polish original. Please refer to the Polish original for more details. Emblem of the Republic of Poland Office for Personal Data Protection Decisions Portal Decision logo Warsaw, July 29, 2026 not final Decision DKN.5131.24.2025 Pursuant to Article 104 § 1 of the Act of June 14, 1960, Code of Administrative Procedure (Journal of Laws of 2025, item 1691), in conjunction with Article 7(1) and (2), Article 10, Article 60, Article 102(1)(1) and (3) of the Act of May 10, 2018, on data protection (Journal of Laws of 2019, Item 1781, as amended), hereinafter referred to as: “the Act of May 10, 2018,” and Art 57(1)(a) and (h), Art 58(2)(i), Art 83(1)–(3), Article 83(4)(a) in conjunction with Article 37(7) and Article 38(6) of Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119 of May 4, 2016, p. 1; OJ EU L 127 of May 23, 2018, p. 2, and Official Journal of the EU L 74 of March 4, 2021, p. 35), hereinafter referred to as “Regulation 2016/679,” following an ex officio administrative proceeding concerning a violation by the Court Bailiff at the District Court in B., H. K., conducting (…) in B. (ul. (…), (…)-(…) B.), of the provisions on data protection, the President of the Personal Data Protection Office: I. finding that the Court Bailiff at the District Court in B. H. K. violated Article 37(7) of Regulation 2016/679 in conjunction with Article 10 of the Act of May 10, 2018, consisting of a failure to notify the supervisory authority of the appointment of a data protection officer within 14 days of the date of such appointment, imposes on the Court Enforcement Officer at the District Court in B. H. K. an administrative fine in the amount of 3,500 PLN (in words: three thousand five hundred zlotys), II. finding that the Court Bailiff at the District Court in B. H. K. violated Article 38(6) of Regulation 2016/679 in connection with the performance, during the period from January 30, 2020, to September 29, 2025, of the function of data protection officer by a person who is a court bailiff, thereby failing to ensure that the other tasks and duties performed by the data protection officer did not give rise to a conflict of interest, imposes on the Court Bailiff at the District Court in B. H. K. an administrative fine in the amount of 12,000 PLN (in words: twelve thousand zlotys). Statement of Reasons 1. The Court Bailiff at the District Court in B. H. K., operating (…) in B. (ul. (…), (…)-(…) B.), hereinafter also referred to as the “Administrator” or “Bailiff,” is an entity whose status and nature of operations are governed by the Act of March 22, 2018, on Court Bailiffs (Journal of Laws of 2024, item 1458, as amended), hereinafter referred to as the “Act on Court Bailiffs.” 2. On April 6, 2023 (date of mailing the notification; date of receipt of the notification by the Office for Personal Data Protection: April 12, 2023), the Controller reported to the President of the Office for Personal Data Protection, hereinafter also referred to as “the President of the UODO” or “the supervisory authority,” a data breach consisting of the erroneous transmission of a copy of a letter addressed to a debtor and informing them of the seizure of a bank account to an unauthorized person (also a debtor). 3. The submitted data breach notification and further explanations provided by the Administrator indicated that the role of data protection officer (hereinafter “DPO”) within the entity’s organizational structure was held at that time by (as of the date of